In plain language
What this advisory means
A weakness in Cisco Secure Firewall ASA and Threat Defense software's handling of DNS over TCP allows attackers to crash the device by sending specially crafted DNS responses. This can cause the firewall to reload, leading to downtime and service interruptions. Attackers must be able to intercept or control DNS responses to exploit this. Cisco has released software updates to fix this issue, but no temporary workarounds exist.
Technical explanation
How the issue affects the environment
Cisco Secure Firewall ASA and Threat Defense software contain a logic error in their DNS over TCP implementation. When parsing DNS queries and tracking buffer sizes, a vulnerability allows crafted DNS replies to cause the TCP DNS response handler to unexpectedly restart. This restart causes the entire device to reload, resulting in a denial-of-service condition. Exploitation requires the attacker to respond to the target's DNS queries, either by controlling the DNS server or performing a man-in-the-middle attack. Cisco has addressed this issue in specific software releases; however, no effective workarounds are available.
Operational impact
Why teams should care
Successful exploitation causes the firewall device to reload, leading to service outages and potential loss of availability. This denial-of-service condition impacts network security operations by interrupting firewall protections and connectivity, potentially exposing enterprise networks to further risk.
Immediate action
Upgrade affected Cisco Secure Firewall ASA and Secure FTD software installations to the fixed releases listed in the advisory to remediate the vulnerability. Cisco strongly recommends applying these updates promptly to prevent exploitation.
Affected and fixed releases
Temporary risk reduction
Cisco states there are no workarounds available that address this vulnerability. Customers must apply software updates to remediate the issue.
Evidence and validation checklist
- Cisco official advisory confirming vulnerability and details
- Detailed vulnerability description and exploitation requirements
- List of affected and fixed software versions
- Statement of no available workarounds
- Acknowledgment of no known public exploitation
- Cisco recommendation to upgrade software
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
