News: 1645603993

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cisco warns firewall customers of four-day window for urgent updates

(2022/02/23)


Cisco has warned users of its Firepower firewalls – physical and virtual – that they may need to upgrade their kit within a four-day window or miss out on security intelligence updates.

A Monday [1]Field Notice advised that the SSL certificate authority used to sign certificates for Talos security intelligence updates will be decommissioned and replaced on March 6, 2022.

The updates deliver lists of sites identified as sources of malware, spam, botnets, and phishing to Cisco appliances, which can automatically apply them so that admins don't have to add to the always-growing list of threats manually.

[2]

But once Cisco changes to the new certificate authority, Firepower devices "might" not be able to receive Talos updates. Snort rule updates, the Cisco Vulnerability Database, and the Geolocation Database will still flow.

[3]Cisco can't say when long waits for hardware will end

[4]The future of work is hybrid, says Cisco, so here's Wi-Fi 6E access points and Private 5G

[5]Cisco inferno: Networking giant reveals three 10/10 rated critical router bugs

[6]Mature networking vendor seeks flexible commitment from software suitors

Users of FirePOWER Services Software for ASA, Firepower Threat Defense (FTD) Software, Firepower Management Center Software, and Firepower 6.1.x through 7.1.x have therefore been advised they'll need to update their software. The update is required for both physical firewalls and FirePOWER running in clouds.

The Field Notice is dated February 2022 and offers a deadline of March 5. It's unpleasantly short notice, but probably an achievable lead time – especially as the necessary updates are already available.

[7]

Except, that is, for those running Firepower 7.1.x, who have been warned that their update is "Planned for release by March 1, 2022."

That's next Tuesday. Four business days from the time of writing, and five days before things break. Not a huge margin for error – it's not like software projects ever run late.

[8]

Or you could rely on Cisco's advice that the certification change merely "might" block updates, and take your chances that crims don't bother reading the Field Notice – which is a public document – or go looking for unpatched boxes on March 6.

Good luck, Firepower users. ®

Get our [9]Tech Resources



[1] https://www.cisco.com/c/en/us/support/docs/field-notices/723/fn72332.html?emailclick=CNSemail

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YhYT3HvWEWK458oMlUkiHQAAAIk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2022/02/17/cisco_q2_2022_shortages/

[4] https://www.theregister.com/2022/02/04/cisco_wifi_6e_private_5g/

[5] https://www.theregister.com/2022/02/04/cisco_smb_routers_critical_vulnerabilities/

[6] https://www.theregister.com/2021/11/24/mature_networking_vendor_seeks_flexible/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YhYT3HvWEWK458oMlUkiHQAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YhYT3HvWEWK458oMlUkiHQAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://whitepapers.theregister.com/



Ouch...

Anonymous Coward

Having worked in banks with strict change controls, 4 days is an awfully short time to get a change in, especially at month end when changes are usually restricted. Normally, any change to a firewall ends up being a high risk change (because if it goes wrong, a LOT of systems stop working) and winds up with a 1-2 week change lead time, change review boards, etc, etc.

Wouldn't surprise me if a lot of places just accept the gap in updates because they can't get the change approvals through to update their kit.

Link here

Skiron

[1]https://status.umbrella.com/#/

I use the Cisco opendns family shield IP's on all devices on my home network - bloody good it is too.

[1] https://status.umbrella.com/#/

Server load

Mishak

Let's hope the download server can take a bit of a beating over a short time window...

As far as we know, our computer has never had an undetected error.
-- Weisert