433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (813) 563-2652

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software DHCP Denial of Service Vulnerability

A vulnerability in the DHCP client functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to exhaust available memory. This vulnerability is due to improper validation of incoming DHCP packets. An attacker could exploit this vulnerability by repeatedly sending crafted DHCPv4 packets to an affected device. A successful exploit could allow the attacker to exhaust available memory, which would affect availability of services and prevent new processes from starting, resulting in a Denial of Service (DoS) condition that would require a manual reboot. Note: On Cisco Secure FTD Software, this vulnerability does not affect management interfaces. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dhcp-qj7nGs4N This advisory is part of the August 2025 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: August 2025 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. Security Impact Rating: Medium CVE: CVE-2025-20135
http://news.poseidon-us.com/TPHfSl

Cisco Secure Firewall Management Center Software Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-xss-JtNmcusP This advisory is part of the August 2025 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: August 2025 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. Security Impact Rating: Medium CVE: CVE-2025-20235
http://news.poseidon-us.com/TPHfSW

Cisco Secure Firewall Management Center Software Authorization Bypass Vulnerabilities

Multiple vulnerabilities in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to access files that they are not authorized to access. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-authz-bypass-M7xhnAu This advisory is part of the August 2025 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: August 2025 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. Security Impact Rating: Medium CVE: CVE-2025-20301,CVE-2025-20302
http://news.poseidon-us.com/TPHfRj

Postmaster general says US Postal Service needs revenue growth, not just cuts

Steiner said the 150-year-old agency needs to expand its revenue base to restore prominence in the nation’s delivery network. The post Postmaster general says US Postal Service needs revenue growth, not just cuts first appeared on Federal News Network.
http://news.poseidon-us.com/TPH1S2

DoD acquisition reform: What will it take to make it last?

“Change is not something that happens by dictate. There has to be an aggressive, intentional, and holistic approach to change management,” Stan Soloway said. The post DoD acquisition reform: What will it take to make it last? first appeared on Federal News Network.
http://news.poseidon-us.com/TPGyBm

DoD acquisition reform: What will it take to make it last?

“Change is not something that happens by dictate. There has to be an aggressive, intentional, and holistic approach to change management,” Stan Soloway said. The post DoD acquisition reform: What will it take to make it last? first appeared on Federal News Network.
http://news.poseidon-us.com/TPGsF0

Army personnel leaders are pushing hard to modernize how the service manages its people

“We need to have systems that are agile and adaptive and could be more up-to-date in the times, in the 21st century,” said Lt. Gen. Brian Eifler The post Army personnel leaders are pushing hard to modernize how the service manages its people first appeared on Federal News Network.
http://news.poseidon-us.com/TPGrsX

Army personnel leaders are pushing hard to modernize how the service manages its people

“We need to have systems that are agile and adaptive and could be more up-to-date in the times, in the 21st century,” said Lt. Gen. Brian Eifler The post Army personnel leaders are pushing hard to modernize how the service manages its people first appeared on Federal News Network.
http://news.poseidon-us.com/TPGrsW

Army personnel leaders are pushing hard to modernize how the service manages its people

“We need to have systems that are agile and adaptive and could be more up-to-date in the times, in the 21st century,” said Lt. Gen. Brian Eifler The post Army personnel leaders are pushing hard to modernize how the service manages its people first appeared on Federal News Network.
http://news.poseidon-us.com/TPGrrl

AI is solving problems it’s also creating

This is the irony of AI in cybersecurity: It can solve problems while simultaneously creating new ones. The post AI is solving problems it’s also creating first appeared on Federal News Network.
http://news.poseidon-us.com/TPGrRT