During penetration testing, a TLS Padding Oracle Vulnerability (Zombie POODLE and GOLDENDOODLE) identified as CVE-2019-1559 was reported on a Cisco Firewall Threat Defense (FTD) device.
The vulnerability was detected on an IP address associated with the an FTD interface.
The vulnerability report raised concerns about potential security exposure requiring investigation and remediation.
HW: Any
SW: Cisco Secure FTD version 7.4.2.4. Other software versions can be also reported.
The reported vulnerability CVE-2019-1559 (TLS Padding Oracle Vulnerability - Zombie POODLE and GOLDENDOODLE) was thoroughly investigated for the FTD device running version 7.4.2.4. The vulnerability scanner has produced a false positive result and the reported device is not impacted by CVE-2019-1559.
No further action was necessary to address this security concern, as the FTD version 7.4.2.4 is not susceptible to the reported TLS Padding Oracle vulnerability.
For additional information, check https://sec.cloudapps.cisco.com/security/center/cvr?cveIdList=CVE-2019-1559#~cve
The vulnerability report was generated by penetration testing tools that identified potential exposure to CVE-2019-1559. However, it was determined that FTD version 7.4.2.4 is not affected by this specific TLS Padding Oracle vulnerability. The cause of the alert was likely a false positive from the vulnerability scanning tool or an incorrect assessment of the susceptibility of this device to this particular CVE.
https://sec.cloudapps.cisco.com/security/center/cvr?cveIdList=CVE-2019-1559#~cve
Cisco bug ID CSCvp80474
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
17-Aug-2026
|
Initial Release |