cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5491
Views
20
Helpful
7
Replies

CSCwa46963 - Security: CVE-2021-44228 -> Log4j 2 Vulnerability

Ralphy006
Level 1
Level 1

Anyone know how FTD via FDM is affected? Is it affected from the outside if there is no management form the outside?

7 Replies 7

yvesjvccnastudy
Level 1
Level 1

The FTDs are presenting https to the outside.

Can that be disabled while non impacting vpn users?

Ralphy006
Level 1
Level 1

unfortunately no one knows yet. We don't even know if shutting off RAVPN is a proper workaround for protecting the firewall from the outside. CRAZY that it's taking so long for a response from Cisco.

I have logged a TAC case.

The reply was along the lines of "what's the emergency?" ( ͠° ͟ʖ ͡°)

 

Gently replied and waiting for TAC to come back and help.

Looks like the hotfix's are coming out on Dec 23rd. Right in time for an upgrade to break out firewalls right before xmas.

 

No details on workaround or conditions.

Ralphy006
Level 1
Level 1

UPDATE: Workaround and Conditions have been added to the BUG

Conditions: Only the FTD-API associated with Firepower Device Manager is vulnerable. This is exposed by default on the management interface and the inside data interface (typically port 2) on devices in the on-device manager mode. This API interface can be disabled by configuration from data-plane interfaces. VPN and other features outside of Firepower Device Manager are not vulnerable. Firepower Management Center managed FTD devices are not vulnerable.

Workaround: Access Control can be added to both the management and data-plane interfaces to limit who can call this FTD-API interface removing the risk from external actors.

Hi Ralphy, can I please ask where you got the details of the Conditions and Workarounds from? Cisco have released a hotfix for FTD 6.4.0 but still no details on how the devices are vulnerable that I can find.

Thanks

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: