Junglewise Threat Intelligence

CVE-2024-20359: Cisco ASA and FTD Privilege Escalation Vulnerability

CVE-2024-20359 · Severity: critical · CVSS 6 · Exploited in the wild · Published 2024-04-24

Technologies: Cisco Adaptive Security Appliance (ASA) Software, Cisco Adaptive Security Appliance (ASA), Cisco Firepower Threat Defense (FTD). Vendors: Cisco.

Executive brief

A vulnerability in Cisco ASA and FTD software allows an authenticated, local attacker with Administrator privileges to execute arbitrary code with root-level privileges. The flaw exists in a legacy capability for preloading VPN clients and plug-ins due to improper validation of files read from system flash memory. Exploitation involves copying a crafted file to the disk0: file system, which executes upon the next device reload and can persist across reboots.

Affected products

  • Cisco Adaptive Security Appliance (ASA) Software
  • Cisco Firepower Threat Defense (FTD) Software

Timeline

  • 2024-04-24: disclosed
  • 2024-04-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-04-24: exploited: Reported as exploited in the wild in association with the ArcaneDoor campaign.

Related threats