⚠ Actively exploited
Added to CISA KEV on 2024-04-24. Federal agencies required to patch by 2024-05-01. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2024-20359Code Injection in Cisco Adaptive Security Appliance Software

CWE-94Code Injection10 documents9 sources
Severity
6.0MEDIUMNVD
EPSS
0.2%
top 63.19%
CISA KEV
KEV
Added 2024-04-24
Due 2024-05-01
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedApr 24
KEV addedApr 24
KEV dueMay 1
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This vulnerability is due to improper validation of a file when it is read from system flash memo

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NExploitability: 0.8 | Impact: 5.2

Affected Packages4 packages

🔴Vulnerability Details

3
GHSA
GHSA-rqwm-368v-fp53: A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Secur2024-04-24
CVEList
CVE-2024-20359: A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Secur2024-04-24
VulnCheck
Cisco ASA and FTD Privilege Escalation Vulnerability2024

📋Vendor Advisories

2
Cisco
Cisco Adaptive Security Appliance and Firepower Threat Defense Software Persistent Local Code Execution Vulnerability2024-04-24
CISA
Cisco ASA and FTD Privilege Escalation Vulnerability2024-04-24

🕵️Threat Intelligence

3
Qualys
ArcaneDoor Attack Exploiting Two Cisco Zero-Day Vulnerabilities2024-04-24
Qualys
ArcaneDoor Espionage: Tactics to Secure Your Network | Qualys2024-04-24
Bleepingcomputer
ArcaneDoor hackers exploit Cisco zero-days to breach govt networks2024-04-24
CVE-2024-20359 — Code Injection in Cisco | cvebase