cbcvebase.
CVE-2024-20353
published 2024-04-24

CVE-2024-20353: A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software…

PriorityP187high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2024-05-01
Exploited in the wild
EPSS
70.69%
99.3th percentile
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.

Affected

535 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance_and_firepower_threat_defense
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://github.com (Cisco ArcaneDoor IOCs)
  • Monitor Cisco ASA/FTD devices for unexpected reboots or unusual outgoing network traffic, which may indicate Line Dancer or Line Runner compromise.
  • Detect exploitation attempts by monitoring for crafted HTTP requests with malformed/incomplete HTTP headers targeting the management and VPN web servers on Cisco ASA/FTD devices.
  • Threat actor UAT4356 (STORM-1849) deployed Line Dancer as an in-memory shellcode interpreter to avoid leaving forensic traces — hunt for anomalous in-memory execution on ASA devices with no corresponding on-disk artifacts.
  • Campaign infrastructure was set up in November 2023 with active malicious activity between December 2023 and early January 2024 — use this timeline to scope log reviews on ASA/FTD devices.
  • ·The initial access vector for the ArcaneDoor campaign exploiting CVE-2024-20353 remains unknown as of the time of disclosure; defenders cannot rely on a known entry-point indicator to scope exposure.
  • ·CVE-2024-20353 is exploitable only when the management or VPN web server feature is enabled on the Cisco ASA/FTD device; organizations with these services disabled are not exposed.

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
vulncheck8.6HIGH
cisa8.6HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.