cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
801
Views
35
Helpful
3
Replies

Cisco Secure Boot Hardware Tampering Vulnerability

Ravi000032
Level 1
Level 1
3 Replies 3

Leo Laohoo
Hall of Fame
Hall of Fame
Without knowing the version the ASA is running, I'd say "yes".

Looking at our ASA's, we are running the following: Fw Version 2.1(9)8.  The advisory says that we need to be running 1.1.15.  So would we need to apply that new version?

Not all ASAs use secure boot. Only the ASA 5506-X (including H and W variants), 5508-X, 5516-X models (sometimes known as "Kenton" models) use that technology. Their ASA software images have "lfbff" in the image name to denote a digitally signed image that is required for secure boot.

The industrial-hardened ISA 3000 also uses secure boot.

All other ASA models do not use secure boot.