SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-20353

Cisco ASA and FTD Denial of Service Vulnerability

KEVHIGH 8.6EPSS 70.7%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 1 May 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.

CVSS 3.1
8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS
70.69% probability · 99th percentile
CISA KEV
Listed 24 April 2024 · due 1 May 2024
Weakness
CWE-835
Affected
cisco/adaptive security appliance software · cisco/secure firewall threat defense
Source
psirt@cisco.com

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2; https://nvd.nist.gov/vuln/detail/CVE-2024-20353

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.