Security News > 2021 > August > Cisco: Firewall manager RCE bug is a zero-day, patch incoming
In a Thursday security advisory update, Cisco revealed that a remote code execution vulnerability in the Adaptive Security Device Manager Launcher disclosed last month is a zero-day bug that has yet to receive a security update.
Cisco ADSM is a firewall appliance manager that provides a web interface for managing Cisco Adaptive Security Appliance firewalls and AnyConnect Secure Mobility clients.
"At the time of publication, Cisco planned to fix this vulnerability in Cisco ASDM," the company says in the updated advisory.
While Cisco PSIRT said that proof-of-concept exploit code was available publicly when the bug was disclosed, it also added that there was no evidence of in the wild abuse.
Cisco revealed the zero-day in November 2020 without security updates addressing the underlying weakness, but it did provide mitigation measures to decrease the attack surface.
Last month, attackers immediately pounced on a Cisco ASA bug, immediately after Positive Technologies' Offensive Team published a PoC exploit.
News URL
Related news
- Cisco Issues Patch for High-Severity VPN Hijacking Bug in Secure Client (source)
- Microsoft March 2024 Patch Tuesday fixes 60 flaws, 18 RCE bugs (source)
- Exploit released for Fortinet RCE bug used in attacks, patch now (source)
- Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs (source)
- Microsoft Fixes 149 Flaws in Huge April Patch Release, Zero-Days Included (source)
- Palo Alto Networks warns of PAN-OS firewall zero-day used in attacks (source)
- Palo Alto Networks zero-day exploited since March to backdoor firewalls (source)
- Week in review: Palo Alto Networks firewalls under attack, Microsoft patches two exploited zero-days (source)
- Palo Alto Networks fixes zero-day exploited to backdoor firewalls (source)
- CrushFTP warns users to patch exploited zero-day “immediately” (source)