Executive brief
A vulnerability in Cisco ASA and FTD software allows an authenticated, local attacker with Administrator privileges to execute arbitrary code with root-level privileges. The flaw exists in a legacy capability for preloading VPN clients and plug-ins due to improper validation of files read from system flash memory. Exploitation involves copying a crafted file to the disk0: file system, which executes upon the next device reload and can persist across reboots.
Affected products
- Cisco Adaptive Security Appliance (ASA) Software
- Cisco Firepower Threat Defense (FTD) Software
Timeline
- 2024-04-24: disclosed
- 2024-04-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-04-24: exploited: Reported as exploited in the wild in association with the ArcaneDoor campaign.