On Tuesday, April 24, 2024, Cisco released advisories concerning multiple high-severity vulnerabilities in their Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software, as part of a response to an ongoing, state-sponsored campaign known as ArcaneDoor. The vulnerabilities — CVE-2024-20353, CVE-2024-20359, and CVE-2024-20358 — were actively exploited to deploy malware and execute commands on compromised devices.
Severity
- CVE-2024-20353 — High, CVSS 8.6/10
- CVE-2024-20359 — Medium, CVSS 6.0/10
- CVE-2024-20358 — Medium, CVSS 6.0/10
Exploitation status: Actively exploited as part of the ArcaneDoor campaign.
Impact
CVE-2024-20353
A vulnerability in the management and VPN web servers for Cisco ASA Software and Cisco FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial-of-service (DoS) condition.
CVE-2024-20359
A vulnerability in a legacy preloading capability for VPN clients and plug-ins in Cisco ASA and Cisco FTD could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability.
CVE-2024-20358
A vulnerability in the Cisco ASA restore functionality (available in Cisco ASA and Cisco FTD) could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. Administrator-level privileges are required to exploit this vulnerability.
Affected products & remediation
Adaptive Security Appliances
| Version | Remediation |
|---|---|
| 9.12.x | Upgrade to 9.12.4.67 |
| 9.14.x | Upgrade to 9.14.4.24 |
| 9.16.x | Upgrade to 9.16.4.57 |
| 9.17.x | Upgrade to 9.17.1.39 |
| 9.18.x | Upgrade to 9.18.4.22 |
| 9.19.x | Upgrade to 9.19.1.28 |
| 9.20.x | Upgrade to 9.20.2.10 |
Firepower Threat Defense
| Version | Remediation |
|---|---|
| 6.4.0 | Upgrade to 6.4.0.18 |
| 6.6.0 | Upgrade to 6.6.7.2 |
| 7.0 | Upgrade to 7.0.6.2 |
| 7.1 | Migrate to a fixed release in a different train |
| 7.2 | Upgrade to 7.2.6 |
| 7.3 | Upgrade to 7.3.1.2 |
| 7.4 | Upgrade to 7.4.1.1 |
Recommendations
Cisco has released software updates addressing these vulnerabilities. There are no workarounds — patches must be applied.
References
- CISA — Cisco Releases Security Updates Addressing ArcaneDoor Vulnerabilities
- Cisco Security Advisory — CVE-2024-20353
- Cisco Security Advisory — CVE-2024-20359
- Cisco Security Advisory — CVE-2024-20358
What Digital Hands is doing
For managed customers, Digital Hands is identifying devices with a vulnerable configuration. Where a vulnerable configuration is found, we'll contact customers to schedule upgrades. If you aren't a Digital Hands customer, follow the directions outlined in the Cisco security advisories to update your appliances as soon as possible. Talk to a Cyber Expert if you'd like Digital Hands to monitor your environment for the next zero-day.