In plain language
What this advisory means
A weakness in certain Cisco Secure Firewall products might allow a nearby attacker to disrupt the device by sending many fake routing messages. This makes the device unexpectedly restart, causing a denial of service. Cisco fixed this issue in updated software versions. There are no simple workarounds, so updating to the fixed software is necessary to protect devices.
Technical explanation
How the issue affects the environment
The vulnerability exists in the Enhanced Interior Gateway Routing Protocol (EIGRP) implementation on Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. Improper resource management when processing crafted EIGRP update messages at a high rate leads to a memory leak. This leak causes the device to reload unexpectedly, resulting in a denial of service (DoS). The exploit requires an unauthenticated attacker with adjacent network access to send malicious EIGRP packets. Cisco addressed this issue in specific software releases, as outlined in their advisory. No workarounds are available; enabling EIGRP authentication can reduce risk but is not a complete mitigation.
Operational impact
Why teams should care
Exploitation of this vulnerability causes affected firewall devices to reload randomly, interrupting network security functions. This unexpected downtime increases the risk of network outages and exposure to threats, potentially impacting business continuity and availability of protected services. Customers should prioritize upgrading to fixed software to maintain network stability and security.
Immediate action
Upgrade affected Cisco Secure Firewall ASA and FTD devices to the fixed software releases provided by Cisco that address this vulnerability. Regularly check for and apply software updates following Cisco's guidance to maintain security posture.
Affected and fixed releases
Temporary risk reduction
There are no workarounds that fully address this vulnerability. Enabling EIGRP authentication across the network can reduce the risk but does not replace upgrading to fixed software.
Evidence and validation checklist
- Cisco Security Advisory cisco-sa-asaftd-eigrp-dos-GOhNejSj
- Detailed vulnerability description and impact
- No public exploit reported
- Fixed software release information
- No workarounds available; mitigation advice on EIGRP authentication
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
