01-23-2023 08:20 AM
Hello,
a vulnerability test detected "TCP Sequence Number Approximation Based Denial of Service" vulnerability (CVE-2004-0230) on a ASA 5506.
The ASA should be running on 9.8(2).
How do I find when (what firmware version) Cisco fixed the vulnerability?
Solved! Go to Solution.
01-23-2023 09:41 AM
I'd be surprised if this is a true positive alert since the CVE (from 2004) was identified 11 years before the ASA 5506 was first released (in 2015). The last software released for the ASA 5506 was 9.16(4)9 in November 2022.
01-23-2023 08:45 AM
Product is EOL - (you need to uplift to latest models - Cisco Secure firewalls (aka FTD)
01-23-2023 09:06 AM
I understand. Would I be able to fix the issue by updating to latest available firmware?
01-23-2023 09:14 AM
where do you get latest firmware and product not sold or giving support by Cisco ?
01-23-2023 09:41 AM
I'd be surprised if this is a true positive alert since the CVE (from 2004) was identified 11 years before the ASA 5506 was first released (in 2015). The last software released for the ASA 5506 was 9.16(4)9 in November 2022.
01-23-2023 09:54 AM
@Marvin Rhoads , I'm not gonna lie, I was waiting for a confirm about this. The CVE is indeed from 2004.
Thank you
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide