Users of Cisco Firepower firewalls have been told that they must upgrade their equipment within the next few days or risk missing out on critical cybersecurity updates.

The SSL certificate authority, which is used to sign certificates for Talos security intelligence updates, will be invalidated on March 5, 2022, according to the company’s Field Notice.

These certificates provide a list of malware distributors, spammers, botnets, and phishing attackers to Cisco endpoints, removing the need for administrators to manually safeguard their equipment.

On the spur of the moment

Some Firepower devices, however, will no longer be eligible for these upgrades as a result of the certificate authority change. It was said that the Cisco Vulnerability Database and the Geolocation Database will continue to get updates.

FirePOWER Services Software for ASA, Firepower Threat Defense (FTD) Software, Firepower Management Center Software, and Firepower 6.1.x – 7.1.x are among the devices[1] that are impacted.

Patching is necessary for both physical firewalls and FirePOWER cloud instances.

The deadline of March 5 is described as “uncomfortably short notice” by the Register, although it is likely to be met on time given that the upgrades are currently available for download. Users using Firepower 7.1.x, on the other hand, should be on the lookout for the update, since their devices have yet to get it.

Cisco said that it will be available “by March 1, 2022.”

The deadline is approaching, and administrators may claim that fraudsters aren’t waiting for the floodgates to open before attacking unpatched firewalls. Cisco equipment, on the other hand, are often targeted by criminals.

A security researcher uncovered a weakness in Cisco’s firewall systems in November of last year, which could be used to cause a denial of service attack (DoS).

The vulnerability, dubbed CVE-2021-34704, was discovered in Cisco’s Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) firewalls, with a CVSSv3.0 score of 8.6.

References

  1. ^ the devices (www.cisco.com)

Source