CERT-Bund warns of unpatched holes in Cisco’s Firepower firewall software
Summary
In August 2019 CERT-Bund warned of four unpatched holes in Cisco’s Firepower firewall software through which attackers could bypass the filter rules without logging in. While CERT-Bund rated the risk as high, Cisco rated all four holes only as “Medium” with CVSS 5.8. At the time of the report there were neither updates nor workarounds.
Ideas
- Prepared packets or data streams could be routed past the firewall’s filters.
- The vendor and national CERTs rated the same holes differently.
- Without a patch, only additional protective measures in the network remained.
Insights
- A firewall that can be bypassed is more dangerous than its CVSS score suggests.
- Risk assessments depend on the context of use, not just on technical severity.
Facts
- CVEs 2019-1978, 2019-1980, 2019-1981 and 2019-1982 were affected.
- Firepower Threat Defense, Firepower Management Center and FirePOWER Services for ASA were affected.
References
Critique
- Why the ratings differ remains open; the report has no response from the CERT.
Recommendations
- Do not rely on a single firewall layer, but segment the network as well.
- Assess the vendor’s severity ratings in your own context and compare them with CERT warnings.
Links to the original source and the Web Archive open in a new tab.