CVE-2024-20353
KEV PoC massUnauthenticated Device-Reload DoS in Cisco ASA and FTD Web Servers
CISA: Cisco ASA and FTD Denial of Service Vulnerability
CVE-2024-20353 is a denial-of-service flaw in the management and VPN web servers of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software, caused by incomplete error checking when parsing an HTTP header (tracked as CWE-835, a loop-exit defect). An unauthenticated, remote attacker can trigger it by sending a crafted HTTP request to the device's web server, causing the firewall/VPN appliance to reload unexpectedly. A successful exploit yields no data theft from the flaw itself but takes the device offline, and repeated requests can sustain an outage of the edge firewall and VPN service. Any organization running ASA or FTD with these web servers reachable by attackers is exposed, which includes nearly every internet-facing Cisco edge deployment. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-24, is referenced in a public Cisco Talos writeup on the ArcaneDoor campaign, where suspected state-sponsored (China-linked) actors chained it with CVE-2024-20359 to backdoor ASA perimeter devices, and EPSS assigns it a 70.7% probability of exploitation within 30 days (99th percentile).
What to do: Upgrade ASA and FTD to the fixed releases listed in Cisco's security advisory (version ranges not included in this data), and because attackers in the ArcaneDoor campaign may have persisted on devices via the related CVE-2024-20359 backdoor, check for unexpected configuration changes or persistence before and after patching. Restrict exposure of the ASA/FTD management and VPN web servers to trusted source addresses while remediation is pending. Per CISA's KEV required action, apply vendor mitigations or discontinue use of the product if mitigations are unavailable.
| Cisco Adaptive Security Appliance (ASA) Software | — |
| Cisco Secure Firewall Threat Defense (FTD) Software | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.
- Affected
- Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- adaptive security appliance software, secure firewall threat defense
- Weakness
- CWE-835
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H