Executive brief
A vulnerability in the management and VPN web servers of Cisco ASA and FTD software allows an unauthenticated remote attacker to cause a denial of service (DoS) by triggering an unexpected device reload. The issue stems from an infinite loop caused by incomplete error checking when parsing crafted HTTP headers.
Affected products
- Cisco Adaptive Security Appliance Software 9.8.1, 9.8.1.5, 9.8.1.7, 9.8.2, 9.8.2.8
- Cisco Firepower Threat Defense Software
Timeline
- 2024-04-24: disclosed
- 2024-04-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-04-24: exploited: Reported as exploited in the wild in an espionage-focused campaign (ArcaneDoor)