09-08-2020 12:32 PM
I have several Cisco ASA 5525-X's and we only run Command Line on them. I can see the ASDM image on the flash but I've never updated it because we don't use it. Would there be a reason to update ASDM if it's not used?
09-08-2020 12:41 PM
Hi,
If you aren't using ASDM, then possibly no need to upgrade.
If however you do need to use ASDM at somepoint in the future, then you should have the latest version to ensure any new feature available in ASA software is configurable via ASDM.
HTH
09-08-2020 12:46 PM
That makes sense, I just want to make sure that if a CVE is published in the future regarding ASDM that I could possible ignore it because it does not apply to my system or if there was not some nuanced functionality that ASDM operated internally that could affect the system software.
09-08-2020 03:43 PM
Personally, my suggestion is - even though you are not using ASDM good to put the latest version which is in line with your ASA version - as part of the upgrade process. - make sure you done all the tick boxes because some auditing not good - they point EOL code in ASA.
09-08-2020 04:37 PM
Whether ASDM is used or not, update or risk getting the network "pwn-ed".
There are a number of ASA vulnerabilities that are actively being exploited.
09-08-2020 05:12 PM
Keep your network sanitized having all patches/software up-to-date. It's the best that you can do to lower the surface and reduce Risk to the business.
09-09-2020 12:16 AM
If you never use it then remove the image from flash and make sure there is no "http server enable" line in the config. That way you don't expose the older (and potentially vulnerable to security-related defects) image.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide