CVE-2024-20353
published 2024-04-24CVE-2024-20353: A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software…
PriorityP187high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2024-05-01
Exploited in the wild
EPSS
70.69%
99.3th percentile
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.
Affected
535 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_and_firepower_threat_defense | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor Cisco ASA/FTD devices for unexpected reboots or unusual outgoing network traffic, which may indicate Line Dancer or Line Runner compromise. ↗
- →Detect exploitation attempts by monitoring for crafted HTTP requests with malformed/incomplete HTTP headers targeting the management and VPN web servers on Cisco ASA/FTD devices. ↗
- →Threat actor UAT4356 (STORM-1849) deployed Line Dancer as an in-memory shellcode interpreter to avoid leaving forensic traces — hunt for anomalous in-memory execution on ASA devices with no corresponding on-disk artifacts. ↗
- →Campaign infrastructure was set up in November 2023 with active malicious activity between December 2023 and early January 2024 — use this timeline to scope log reviews on ASA/FTD devices. ↗
- ·The initial access vector for the ArcaneDoor campaign exploiting CVE-2024-20353 remains unknown as of the time of disclosure; defenders cannot rely on a known entry-point indicator to scope exposure. ↗
- ·CVE-2024-20353 is exploitable only when the management or VPN web server feature is enabled on the Cisco ASA/FTD device; organizations with these services disabled are not exposed. ↗
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
vulncheck8.6HIGH
cisa8.6HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance and Firepower Threat Defense Software Web Services Denial of Service Vulnerability
vendor_cisco·2024-04-24·CVSS 8.6
CVE-2024-20353 [HIGH] CWE-835 Cisco Adaptive Security Appliance and Firepower Threat Defense Software Web Services Denial of Service Vulnerability
Cisco Adaptive Security Appliance and Firepower Threat Defense Software Web Services Denial of Service Vulnerability
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.
Cisco has released software updates that address this vulnerability. There are no wo
CISA
Cisco ASA and FTD Denial of Service Vulnerability
cisa·2024-04-24·CVSS 8.6
CVE-2024-20353 [HIGH] CWE-835 Cisco ASA and FTD Denial of Service Vulnerability
Vulnerability: Cisco ASA and FTD Denial of Service Vulnerability
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2; https://nvd.nist.gov/vuln/detail/CVE-2024-20353
Remediation Due Date: 2024-05-01
Cisco
Cisco Adaptive Security Appliance and Firepower Threat Defense Software Web Services Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20353 Cisco Adaptive Security Appliance and Firepower Threat Defense Software Web Services Denial of Service Vulnerability
CVE-2024-20353: Cisco Adaptive Security Appliance and Firepower Threat Defense Software Web Services Denial of Service Vulnerability
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads. Cisco has released software updates that address this vulnerability. Th
GHSA
GHSA-pp78-fggv-r899: A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) So
ghsa_unreviewed·2024-04-24
CVE-2024-20353 [HIGH] CWE-835 GHSA-pp78-fggv-r899: A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) So
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.
VulnCheck
Cisco ASA and FTD Denial of Service Vulnerability
vulncheck·2024·CVSS 8.6
CVE-2024-20353 [HIGH] CWE-835 Cisco ASA and FTD Denial of Service Vulnerability
Cisco ASA and FTD Denial of Service Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2; https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_attacks_event_response; https://www.cisa.gov/news-events/alerts/2024/04/24/cisco-releases-security-updates-addressing-arcane
No detection rules found.
No public exploits indexed.
Bleepingcomputer
CISA warns feds to fully patch actively exploited Cisco flaws
blogs_bleepingcomputer·2025-11-13·CVSS 8.6
CVE-2025-20362 [HIGH] CISA warns feds to fully patch actively exploited Cisco flaws
## CISA warns feds to fully patch actively exploited Cisco flaws
## Sergiu Gatlan
CISA warned U.S. federal agencies to fully patch two actively exploited vulnerabilities in Cisco Adaptive Security Appliances (ASA) and Firepower devices.
Tracked as CVE-2025-20362 and CVE-2025-20333 , these security flaws allow remote threat actors to access restricted URL endpoints without authentication and gain code execution on vulnerable Cisco firewall devices, respectively. If chained, they can enable unauthenticated attackers to gain complete control of unpatched devices remotely.
When it patched the two flaws in September, Cisco cautioned customers that they had been exploited as zero-days in attacks targeting 5500-X Series devices with VPN web services enabled. The company also linked these atta
Bleepingcomputer
Cisco: Actively exploited firewall flaws now abused for DoS attacks
blogs_bleepingcomputer·2025-11-07·CVSS 9.9
CVE-2025-20362 [CRITICAL] Cisco: Actively exploited firewall flaws now abused for DoS attacks
## Cisco: Actively exploited firewall flaws now abused for DoS attacks
## Sergiu Gatlan
Cisco warned this week that two vulnerabilities, which have been used in zero-day attacks, are now being exploited to force ASA and FTD firewalls into reboot loops.
The tech giant released security updates on September 25 to address the two security flaws, stating that CVE-2025-20362 enables remote threat actors to access restricted URL endpoints without authentication, while CVE-2025-20333 allows authenticated attackers to gain remote code execution on vulnerable devices.
When chained, these vulnerabilities allow remote, unauthenticated attackers to gain complete control over unpatched systems.
The same day, CISA issued an emergency directive ordering U.S. federal agencies to secure their Cisco fi
Zscaler
Cisco Firewall and VPN Zero Day Attacks | ThreatLabz
blogs_zscaler·2025-09-26·CVSS 9.9
[CRITICAL] Cisco Firewall and VPN Zero Day Attacks | ThreatLabz
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bleepingcomputer
CISA orders agencies to patch Cisco flaws exploited in zero-day attacks
blogs_bleepingcomputer·2025-09-25·CVSS 9.9
CVE-2025-20333 [CRITICAL] CISA orders agencies to patch Cisco flaws exploited in zero-day attacks
## CISA orders agencies to patch Cisco flaws exploited in zero-day attacks
## Sergiu Gatlan
CISA has issued a new emergency directive ordering U.S. federal agencies to secure their Cisco firewall devices against two flaws that have been exploited in zero-day attacks.
Emergency Directive 25-03 was issued to Federal Civilian Executive Branch (FCEB) agencies on September 25 and requires them to patch CVE-2025-20333 and CVE-2025-20362 vulnerabilities in Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) software.
"The campaign is widespread and involves exploiting zero-day vulnerabilities to gain unauthenticated remote code execution on ASAs, as well as manipulating read-only memory (ROM) to persist through reboot and system upgrade. This activity presents a significant ri
Tenable
CVE-2025-20333, CVE-2025-20362: Cisco Zero-Days Exploited | Tenable®
blogs_tenable·2025-09-25·CVSS 9.9
[CRITICAL] CVE-2025-20333, CVE-2025-20362: Cisco Zero-Days Exploited | Tenable®
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Verizon 2025 DBIR: Tenable Research Collaboration Shines a Spotlight on CVE Remediation Trends
blogs_tenable·2025-04-23
Verizon 2025 DBIR: Tenable Research Collaboration Shines a Spotlight on CVE Remediation Trends
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Cisco warns of backdoor admin account in Smart Licensing Utility
blogs_bleepingcomputer·2024-09-04·CVSS 9.8
CVE-2024-20439 [CRITICAL] Cisco warns of backdoor admin account in Smart Licensing Utility
## Cisco warns of backdoor admin account in Smart Licensing Utility
## Sergiu Gatlan
Cisco has removed a backdoor account in the Cisco Smart Licensing Utility (CSLU) that can be used to log into unpatched systems with administrative privileges.
CSLU is a Windows application that helps manage licenses and linked products on-premises without connecting them to Cisco's cloud-based Smart Software Manager solution.
The company says this critical vulnerability (CVE-2024-20439) allows unauthenticated attackers to log into unpatched systems remotely using an "undocumented static user credential for an administrative account."
"A successful exploit could allow the attacker to log in to the affected system with administrative privileges over the API of the Cisco Smart Licensing Utility applicat
Bleepingcomputer
Cisco SSM On-Prem bug lets hackers change any user's password
blogs_bleepingcomputer·2024-07-17·CVSS 8.6
[HIGH] Cisco SSM On-Prem bug lets hackers change any user's password
## Cisco SSM On-Prem bug lets hackers change any user's password
## Sergiu Gatlan
Cisco has fixed a maximum severity vulnerability that allows attackers to change any user's password on vulnerable Cisco Smart Software Manager On-Prem (Cisco SSM On-Prem) license servers, including administrators.
The flaw also impacts SSM On-Prem installations earlier than Release 7.0, known as Cisco Smart Software Manager Satellite (SSM Satellite).
As a Cisco Smart Licensing component, SSM On-Prem assists service providers and Cisco partners in managing customer accounts and product licenses.
Tracked as CVE-2024-20419, this critical security flaw is caused by an unverified password change weakness in SSM On-Prem's authentication system. Successful exploitation enables unauthenticated, remote attackers
Talos
Inside the ransomware playbook: Analyzing attack chains and mapping common TTPs
blogs_talos·2024-07-10
Inside the ransomware playbook: Analyzing attack chains and mapping common TTPs
Given the recent slate of massive ransomware attacks that have disrupted everything from hospitals to car dealerships, Cisco Talos wanted to take a renewed look at the top ransomware players to see where the current landscape stands.
Based on a comprehensive review of more than a dozen prominent ransomware groups, we identified several commonalities in tactics, techniques and procedures (TTPs), along with several notable differences and outliers.
Talos’ studies indicate that the most prolific ransomware actors prioritize gaining initial access to targeted networks, with valid accounts being the most common mechanism. Phishing for credentials often precedes these attacks, a trend observed across all incident response engagements, consistent with our 2023 Year in Review report. Over the pa
Talos
Inside the ransomware playbook: Analyzing attack chains and mapping common TTPs
blogs_talos·2024-07-10
Inside the ransomware playbook: Analyzing attack chains and mapping common TTPs
## Inside the ransomware playbook: Analyzing attack chains and mapping common TTPs
Given the recent slate of massive ransomware attacks that have disrupted everything from hospitals to car dealerships , Cisco Talos wanted to take a renewed look at the top ransomware players to see where the current landscape stands.
Based on a comprehensive review of more than a dozen prominent ransomware groups, we identified several commonalities in tactics, techniques and procedures (TTPs), along with several notable differences and outliers.
Talos’ studies indicate that the most prolific ransomware actors prioritize gaining initial access to targeted networks, with valid accounts being the most common mechanism. Phishing for credentials often precedes these attacks, a trend observed across all incid
Bleepingcomputer
Norway recommends replacing SSL VPN to prevent breaches
blogs_bleepingcomputer·2024-05-16
Norway recommends replacing SSL VPN to prevent breaches
## Norway recommends replacing SSL VPN to prevent breaches
## Bill Toulas
The Norwegian National Cyber Security Centre (NCSC) recommends replacing SSLVPN/WebVPN solutions with alternatives due to the repeated exploitation of related vulnerabilities in edge network devices to breach corporate networks.
The organization recommends that the transition be completed by 2025, while organizations subject to the 'Safety Act' or those in critical infrastructure should adopt safer alternatives by the end of 2024.
NCSC's official recommendation for users of Secure Socket Layer Virtual Private Network (SSL VPN/WebVPN) products is to switch to Internet Protocol Security (IPsec) with Internet Key Exchange (IKEv2).
SSL VPN and WebVPN provide secure remote access to a network over the internet using
Tenable
CVE-2024-20353, CVE-2024-20359: Frequently Asked Questions About ArcaneDoor
blogs_tenable·2024-04-25·CVSS 8.6
[HIGH] CVE-2024-20353, CVE-2024-20359: Frequently Asked Questions About ArcaneDoor
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
ArcaneDoor Attack Exploiting Two Cisco Zero-Day Vulnerabilities
blogs_qualys·2024-04-24·CVSS 8.6
CVE-2024-20353 [HIGH] ArcaneDoor Attack Exploiting Two Cisco Zero-Day Vulnerabilities
## Table of Contents
Technical Insight of ArcaneDoor Vulnerability
How Qualys Can Help You Detect and Stop the ArcaneDoor Vulnerability
Qualys QID Coverage
Conclusion
Cisco recently uncovered a sophisticated cyber espionage campaign, ArcaneDoor, targeting perimeter network devices used by government and critical infrastructure sectors. This campaign involves state-sponsored actors exploiting two zero-day vulnerabilities ( CVE-2024-20353 and CVE-2024-20359 ) aimed primarily at espionage through intricate malware known as Line Runner and Line Dancer.
ArcaneDoor manipulates perimeter network devices, such as Cisco Adaptive Security Appliances (ASA), to reroute or monitor network traffic, providing a strategic vantage point for espionage. The investigation, spurred by vigilant customer r
Talos
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
blogs_talos·2024-04-24·CVSS 9.9
CVE-2025-20333 [CRITICAL] ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
## ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
*Update 2025-09-25: Cisco is aware of new activity targeting certain Cisco Adaptive Security Appliances (ASA) 5500-X Series and has released three CVE’s related to the event: CVE-2025-20333 , CVE-2025-20362 and CVE-2025-20363 . The following Snort Rules cover these vulnerabilities: 65340, 46897.
We assess with high confidence this activity is related to same threat actor as ArcaneDoor in 2024.
We strongly recommend that Cisco customers upgrade their devices to the available fixed software and follow guidance in the security advisories.
*Updated 2024-04-25 16:57 GMT with minor wording corrections regarding the targeting of other vendors. ArcaneDoor is a campaign that is the latest example of state-s
Talos
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
blogs_talos·2024-04-24·CVSS 9.9
CVE-2025-20333 [CRITICAL] ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
*Update 2025-09-25: Cisco is aware of new activity targeting certain Cisco Adaptive Security Appliances (ASA) 5500-X Series and has released three CVE’s related to the event: CVE-2025-20333, CVE-2025-20362 and CVE-2025-20363. The following Snort Rules cover these vulnerabilities: 65340, 46897.
We assess with high confidence this activity is related to same threat actor as ArcaneDoor in 2024.
We strongly recommend that Cisco customers upgrade their devices to the available fixed software and follow guidance in the security advisories.
*Updated 2024-04-25 16:57 GMT with minor wording corrections regarding the targeting of other vendors.
ArcaneDoor is a campaign that is the latest example of state-sponsored actors targeting perimeter network devices from multiple vendors. Coveted by these
Qualys
ArcaneDoor Espionage: Tactics to Secure Your Network | Qualys
blogs_qualys·2024-04-24·CVSS 8.6
CVE-2024-20353 [HIGH] ArcaneDoor Espionage: Tactics to Secure Your Network | Qualys
#### Table of Contents
- Technical Insight of ArcaneDoor Vulnerability
- How Qualys Can Help You Detect and Stop the ArcaneDoor Vulnerability
- Qualys QID Coverage
- Conclusion
Cisco recently uncovered a sophisticated cyber espionage campaign, ArcaneDoor, targeting perimeter network devices used by government and critical infrastructure sectors. This campaign involves state-sponsored actors exploiting two zero-day vulnerabilities (CVE-2024-20353 and CVE-2024-20359) aimed primarily at espionage through intricate malware known as Line Runner and Line Dancer.
ArcaneDoor manipulates perimeter network devices, such as Cisco Adaptive Security Appliances (ASA), to reroute or monitor network traffic, providing a strategic vantage point for espionage. The investigation, spurred by vigilant custo
Bleepingcomputer
ArcaneDoor hackers exploit Cisco zero-days to breach govt networks
blogs_bleepingcomputer·2024-04-24·CVSS 8.6
[HIGH] ArcaneDoor hackers exploit Cisco zero-days to breach govt networks
## ArcaneDoor hackers exploit Cisco zero-days to breach govt networks
## Sergiu Gatlan
Cisco warned today that a state-backed hacking group has been exploiting two zero-day vulnerabilities in Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls since November 2023 to breach government networks worldwide.
The hackers, identified as UAT4356 by Cisco Talos and STORM-1849 by Microsoft, began infiltrating vulnerable edge devices in early November 2023 in a cyber-espionage campaign tracked as ArcaneDoor.
Even though Cisco has not yet identified the initial attack vector, it discovered and fixed two security flaws— CVE-2024-20353 (denial of service) and CVE-2024-20359 (persistent local code execution)—that the threat actors used as zero-days in these attacks.
Cisco
Zscaler
Replace Cisco Umbrella Secure Internet Gateway (SIG) | ZIA
blogs_zscaler
Replace Cisco Umbrella Secure Internet Gateway (SIG) | ZIA
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-20353
2024-04-24
Published
2024-04-24
Added to CISA KEV
Exploited in the wild