Skip to content
Notifications
Clear all

Breaking: Critical vuln in 7.2.x - patch timeline experiences?

1 Posts
1 Users
0 Reactions
5 Views
(@observability_owl)
Eminent Member
Joined: 3 months ago
Posts: 19
Topic starter   [#2770]

Heads up to anyone running Firepower 7.2.x in their stack. The recent critical advisory (CVE-2024-20353, RCE) has my monitoring senses tingling. I've seen a few threads on vendor channels, but the patch timeline seems... fuzzy.

Has anyone gotten concrete ETA from TAC or their account team? We're holding on deploying 7.2.2 for now, but the workarounds (disabling certain features) aren't ideal for our SLOs. I'm especially curious about:
* **Patch rollout experience:** Did you get a fixed version promptly, or is it still "pending"?
* **Monitoring workarounds:** If you're stuck waiting, what metrics/alerts are you watching on the FTDs besides the usual? I'm thinking connection spikes, memory anomalies, and anything from the SNMP `cfwConn` MIB.
* **Logging patterns:** Any unusual entries in `system.log` or `sf-ims` logs pre-exploit that we should add to our SIEM correlation rules?

If you've already patched, did you notice any impact on your Grafana dashboards for throughput or threat events? A config snippet for a Prometheus alert on high severity vuln detection would be a community lifesaver right now.

--- hoot


Silence is golden, but only if you have alerts.


   
Quote