cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
680
Views
5
Helpful
2
Replies

ASA BGP Bidirectional Forwarding Detection ACL Bypass Vulnerability

Hi Guys,

We recently had an auditor flag our ASA for the ASA BGP Bidirectional Forwarding Detection ACL Bypass Vulnerability (CSCvc68229).

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-asa

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvc68229

My question is, if we are not actively running BGP on the ASA are we still vulnerable?

Thanks,

Scott

2 Replies 2

Philip D'Ath
VIP Alumni
VIP Alumni

If you are not running BGP then I would say you are not vulnerable.

n.oneill
Level 1
Level 1

"Conditions:
The issue affects ASA software version 9.6(2) and later. No specific configuration is required."

 

I don't think it matters if BGP is configured or not.