Executive brief
A vulnerability in Cisco's firewall software could allow an attacker to perform browser-based attacks against users of the VPN service. By tricking a user into visiting a malicious website, an attacker can reflect harmful code through the firewall and into the user's browser. This could lead to unauthorized actions being performed on behalf of the user, though the firewall device itself is not directly compromised.
Technical details
A vulnerability in the VPN web services component of Cisco ASA and FTD software (CWE-444) arises from improper validation of HTTP requests. An unauthenticated, remote attacker can exploit this by persuading a user to visit a malicious website that sends specially crafted HTTP requests to the firewall's VPN endpoints (specifically SSL VPN or IKEv2 with client services enabled). This results in a client-side request smuggling or reflected XSS attack where malicious input is reflected back to the user's browser. While the attacker cannot directly impact the device's integrity or availability, they can execute scripts in the context of the user's session. Fixed software versions have been released to address this issue.
Affected products
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1 to 9.16.4.85, 9.17.1 to 9.18.4.66, 9.19.1 to 9.20.4, 9.22.1.1 to 9.22.2.4, 9.23.1 to 9.23.1.7
- Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0 to 7.0.9, 7.1.0 to 7.2.11, 7.3.0 to 7.4.3, 7.6.0 to 7.6.4, 7.7.0 to 7.7.11
Timeline
- 2026-03-04: advisory: Initial advisory published by Cisco
- 2026-03-04: disclosed
- 2026-06-02: other: NVD analysis and CPE information updated