Security Bulletin

Cisco Adaptive Security Appliance and Firepower Threat Defense Vulnerabilities

A security bulletin from the Digital Hands SOC covering newly disclosed vulnerabilities in Cisco ASA and Firepower Threat Defense — affected versions, exploitation context, and recommended actions.

On Tuesday, April 24, 2024, Cisco released advisories concerning multiple high-severity vulnerabilities in their Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software, as part of a response to an ongoing, state-sponsored campaign known as ArcaneDoor. The vulnerabilities — CVE-2024-20353, CVE-2024-20359, and CVE-2024-20358 — were actively exploited to deploy malware and execute commands on compromised devices.

Severity

Exploitation status: Actively exploited as part of the ArcaneDoor campaign.

Impact

CVE-2024-20353

A vulnerability in the management and VPN web servers for Cisco ASA Software and Cisco FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial-of-service (DoS) condition.

CVE-2024-20359

A vulnerability in a legacy preloading capability for VPN clients and plug-ins in Cisco ASA and Cisco FTD could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability.

CVE-2024-20358

A vulnerability in the Cisco ASA restore functionality (available in Cisco ASA and Cisco FTD) could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. Administrator-level privileges are required to exploit this vulnerability.

Affected products & remediation

Adaptive Security Appliances

VersionRemediation
9.12.xUpgrade to 9.12.4.67
9.14.xUpgrade to 9.14.4.24
9.16.xUpgrade to 9.16.4.57
9.17.xUpgrade to 9.17.1.39
9.18.xUpgrade to 9.18.4.22
9.19.xUpgrade to 9.19.1.28
9.20.xUpgrade to 9.20.2.10

Firepower Threat Defense

VersionRemediation
6.4.0Upgrade to 6.4.0.18
6.6.0Upgrade to 6.6.7.2
7.0Upgrade to 7.0.6.2
7.1Migrate to a fixed release in a different train
7.2Upgrade to 7.2.6
7.3Upgrade to 7.3.1.2
7.4Upgrade to 7.4.1.1

Recommendations

Cisco has released software updates addressing these vulnerabilities. There are no workarounds — patches must be applied.

References

  1. CISA — Cisco Releases Security Updates Addressing ArcaneDoor Vulnerabilities
  2. Cisco Security Advisory — CVE-2024-20353
  3. Cisco Security Advisory — CVE-2024-20359
  4. Cisco Security Advisory — CVE-2024-20358

What Digital Hands is doing

For managed customers, Digital Hands is identifying devices with a vulnerable configuration. Where a vulnerable configuration is found, we'll contact customers to schedule upgrades. If you aren't a Digital Hands customer, follow the directions outlined in the Cisco security advisories to update your appliances as soon as possible. Talk to a Cyber Expert if you'd like Digital Hands to monitor your environment for the next zero-day.

Back to Blog

Ready to Get There First?

Talk to a Cyber Expert