CVE-2024-20353
Cisco ASA and FTD Denial of Service Vulnerability
Description
CVE-2024-20353 is a high-severity denial of service vulnerability in the management and VPN web servers of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software. An unauthenticated remote attacker can cause the device to reload unexpectedly by sending a specially crafted HTTP request, resulting in a denial of service condition that disrupts all traffic passing through the security appliance. With a CVSS v3.1 base score of 8.6 and a changed scope, the vulnerability's impact extends beyond the appliance itself to all network services dependent on it. CISA has added CVE-2024-20353 to the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of May 1, 2024, and its EPSS score of 19.54% at the 95.3rd percentile confirms high exploitation probability, particularly as part of the ArcaneDoor espionage campaign.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HOpen in CalculatorCWEs
Affected Products
| Vendor | Product | Version |
|---|---|---|
| cisco | adaptive security appliance software | 9.8.1; 9.8.1.5; 9.8.1.7; 9.8.2; 9.8.2.8; 9.8.2.14; 9.8.2.15; 9.8.2.17; 9.8.2.20; 9.8.2.24; 9.8.2.26; 9.8.2.28; 9.8.2.33; 9.8.2.35; 9.8.2.38; 9.8.3; 9.8.3.8; 9.8.3.11; 9.8.3.14; 9.8.3.16; 9.8.3.18; 9.8.3.21; 9.8.3.26; 9.8.3.29; 9.8.4; 9.8.4.3; 9.8.4.7; 9.8.4.8; 9.8.4.10; 9.8.4.12; 9.8.4.15; 9.8.4.17; 9.8.4.20; 9.8.4.22; 9.8.4.25; 9.8.4.26; 9.8.4.29; 9.8.4.32; 9.8.4.33; 9.8.4.34; 9.8.4.35; 9.8.4.39; 9.8.4.40; 9.8.4.41; 9.8.4.43; 9.8.4.44; 9.8.4.45; 9.8.4.46; 9.8.4.48; 9.12.1; 9.12.1.2; 9.12.1.3; 9.12.2; 9.12.2.1; 9.12.2.4; 9.12.2.5; 9.12.2.9; 9.12.3; 9.12.3.2; 9.12.3.7; 9.12.3.9; 9.12.3.12; 9.12.4; 9.12.4.2; 9.12.4.4; 9.12.4.7; 9.12.4.8; 9.12.4.10; 9.12.4.13; 9.12.4.18; 9.12.4.24; 9.12.4.26; 9.12.4.29; 9.12.4.30; 9.12.4.35; 9.12.4.37; 9.12.4.38; 9.12.4.39; 9.12.4.40; 9.12.4.41; 9.12.4.47; 9.12.4.48; 9.12.4.50; 9.12.4.52; 9.12.4.54; 9.12.4.55; 9.12.4.56; 9.12.4.58; 9.12.4.62; 9.12.4.65; 9.14.1; 9.14.1.6; 9.14.1.10; 9.14.1.15; 9.14.1.19; 9.14.1.30; 9.14.2; 9.14.2.4; 9.14.2.8; 9.14.2.13; 9.14.2.15; 9.14.3; 9.14.3.1; 9.14.3.9; 9.14.3.11; 9.14.3.13; 9.14.3.15; 9.14.3.18; 9.14.4; 9.14.4.6; 9.14.4.7; 9.14.4.12; 9.14.4.13; 9.14.4.14; 9.14.4.15; 9.14.4.17; 9.14.4.22; 9.14.4.23; 9.15.1; 9.15.1.1; 9.15.1.7; 9.15.1.10; 9.15.1.15; 9.15.1.16; 9.15.1.17; 9.15.1.21; 9.16.1; 9.16.1.28; 9.16.2; 9.16.2.3; 9.16.2.7; 9.16.2.11; 9.16.2.13; 9.16.2.14; 9.16.3; 9.16.3.3; 9.16.3.14; 9.16.3.15; 9.16.3.19; 9.16.3.23; 9.16.4; 9.16.4.9; 9.16.4.14; 9.16.4.18; 9.16.4.19; 9.16.4.27; 9.16.4.38; 9.16.4.39; 9.16.4.42; 9.16.4.48; 9.16.4.55; 9.17.1; 9.17.1.7; 9.17.1.9; 9.17.1.10; 9.17.1.11; 9.17.1.13; 9.17.1.15; 9.17.1.20; 9.17.1.30; 9.17.1.33; 9.18.1; 9.18.1.3; 9.18.2; 9.18.2.5; 9.18.2.7; 9.18.2.8; 9.18.3; 9.18.3.39; 9.18.3.46; 9.18.3.53; 9.18.3.55; 9.18.3.56; 9.18.4; 9.18.4.5; 9.18.4.8; 9.19.1; 9.19.1.5; 9.19.1.9; 9.19.1.12; 9.19.1.18; 9.19.1.22; 9.19.1.24; 9.19.1.27; 9.20.1; 9.20.1.5; 9.20.2 |
| cisco | secure firewall threat defense | 6.2.3; 6.2.3.1; 6.2.3.2; 6.2.3.3; 6.2.3.4; 6.2.3.5; 6.2.3.6; 6.2.3.7; 6.2.3.8; 6.2.3.9; 6.2.3.10; 6.2.3.11; 6.2.3.12; 6.2.3.13; 6.2.3.14; 6.2.3.15; 6.2.3.16; 6.2.3.17; 6.2.3.18; 6.4.0; 6.4.0.1; 6.4.0.2; 6.4.0.3; 6.4.0.4; 6.4.0.5; 6.4.0.6; 6.4.0.7; 6.4.0.8; 6.4.0.9; 6.4.0.10; 6.4.0.11; 6.4.0.12; 6.4.0.13; 6.4.0.14; 6.4.0.15; 6.4.0.16; 6.4.0.17; 6.6.0; 6.6.0.1; 6.6.1; 6.6.3; 6.6.4; 6.6.5; 6.6.5.1; 6.6.5.2; 6.6.7; 6.6.7.1; 6.7.0; 6.7.0.1; 6.7.0.2; 6.7.0.3; 7.0.0; 7.0.0.1; 7.0.1; 7.0.1.1; 7.0.2; 7.0.2.1; 7.0.3; 7.0.4; 7.0.5; 7.0.6; 7.0.6.1; 7.1.0; 7.1.0.1; 7.1.0.2; 7.1.0.3; 7.2.0; 7.2.0.1; 7.2.1; 7.2.2; 7.2.3; 7.2.4; 7.2.4.1; 7.2.5; 7.2.5.1; 7.3.0; 7.3.1; 7.3.1.1; 7.4.0; 7.4.1 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2(Vendor Advisory)
- https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/(Exploit, Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-20353(US Government Resource)
Weakness Type
Incomplete HTTP Header Parsing Error
CVE-2024-20353 is caused by incomplete error checking when parsing HTTP headers in the management and VPN web server components of Cisco ASA and FTD software. When the web server receives an HTTP request with a malformed header, the parsing logic encounters an error condition that is not properly handled, leading to a crash in the web server process that causes the entire device to reload. This weakness maps to CWE-400 (Uncontrolled Resource Consumption) and is closely related to CWE-20 (Improper Input Validation), where insufficient validation of HTTP header content leads to unhandled error conditions that crash the system. The incomplete error handling in a network-facing service on a critical perimeter security device creates a reliable remote denial of service attack vector. Learn more about CWE-20
Impact Analysis
The business impact of CVE-2024-20353 is severe, particularly due to the changed scope (S:C) that extends the denial of service beyond the vulnerable appliance to all downstream systems and services. Availability is rated high because a successful attack causes the Cisco ASA or FTD device to reload, dropping all active connections including VPN tunnels, firewall-protected traffic flows, and management sessions. For organizations where the ASA or FTD serves as the primary perimeter firewall or VPN concentrator, this results in a complete network outage for the duration of the device restart, typically several minutes. Repeated exploitation can maintain a persistent denial of service condition.
Confidentiality and Integrity are not directly impacted (C:N/I:N) by the denial of service itself, but the network disruption creates secondary risks. During the device reload, traffic that would normally be inspected by the firewall may be routed through failover paths with reduced security controls, and VPN users lose encrypted connectivity, potentially falling back to unencrypted communications. Additionally, the ArcaneDoor campaign context suggests this vulnerability may be used as a diversionary tactic or to force device reboots that trigger the execution of persistent backdoors installed through companion vulnerabilities like CVE-2024-20359.
The attack requires no authentication (PR:N), no user interaction (UI:N), and can be executed remotely (AV:N) with low complexity (AC:L). The EPSS score of 19.54% at the 95.3rd percentile indicates that approximately one in five observable attack opportunities results in exploitation. CISA classifies the ransomware association as "Unknown."
Exploit Maturity
CVE-2024-20353 has been confirmed as actively exploited in the wild as part of the ArcaneDoor espionage campaign documented by Cisco Talos Intelligence. The ArcaneDoor campaign is a state-sponsored operation that specifically targets Cisco ASA perimeter devices using multiple vulnerabilities, including CVE-2024-20353 and its companion vulnerability CVE-2024-20359.
Cisco disclosed the vulnerability through security advisory cisco-sa-asaftd-websrvs-dos-X8gNucD2, confirming active exploitation during the ArcaneDoor investigation. The EPSS score of 19.54% at the 95.3rd percentile places this vulnerability among the top 5% for exploitation probability, reflecting both the ease of exploitation (a single crafted HTTP request) and the widespread deployment of vulnerable Cisco ASA and FTD devices across enterprise networks. In the ArcaneDoor campaign context, this denial of service vulnerability appears to serve a supporting role alongside CVE-2024-20359, potentially being used to force device reboots that trigger the execution of previously installed persistent backdoors. The ransomware association is classified as "Unknown" by CISA, and the primary exploitation context is espionage rather than financial crime.
Remediation
-
Apply Cisco security updates as an emergency priority by upgrading Cisco ASA and FTD software to a fixed version as specified in Cisco's security advisory. Given the confirmed exploitation in the ArcaneDoor espionage campaign, this should be treated as the highest priority.
-
Restrict access to the management and VPN web servers by implementing access control lists (ACLs) that limit which IP addresses can reach the HTTPS management interface and the VPN portal. Reduce exposure by ensuring that the management interface is not accessible from the public internet and restricting VPN portal access to known IP ranges where feasible.
-
Deploy high-availability configurations if not already in place, to minimize the impact of device reloads caused by exploitation. Active/standby or active/active failover configurations ensure that traffic continues to flow through the standby unit while the primary recovers from a crash, reducing the duration of service disruption.
-
Monitor for exploitation indicators by configuring syslog alerts for unexpected device reloads, web server crashes, and malformed HTTP requests. Correlate ASA/FTD crash events with external connection data to identify the source of exploitation attempts. Review the ArcaneDoor indicators of compromise published by Cisco Talos.
-
Assess for companion vulnerability exploitation by checking whether CVE-2024-20359 has also been exploited on your devices. The ArcaneDoor campaign uses both vulnerabilities together, so evidence of CVE-2024-20353 exploitation may indicate that persistent backdoors have been installed through CVE-2024-20359. Follow Cisco's integrity verification procedures to examine the device for unauthorized modifications.
Technical Details
CVE-2024-20353 is a denial of service vulnerability in the management and VPN web servers of Cisco ASA and FTD Software. The CVSS v3.1 vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H, resulting in a base score of 8.6 (High).
The vulnerability exists in the HTTP header parsing logic of the web server components that handle management interface requests and VPN portal connections. When the web server receives an HTTP request containing a specially crafted header, the parsing function encounters an error condition due to incomplete error checking. The error causes an unhandled exception or memory corruption in the web server process, which triggers the ASA or FTD device's crash handler. Because the web server runs as a critical system process, its crash causes the entire device to reload, dropping all active connections and network traffic.
The Attack Vector (AV:N) confirms fully remote exploitation through the network. The attacker only needs to be able to send HTTP requests to the ASA/FTD management interface or VPN web portal. Attack Complexity (AC:L) is low because the exploit requires only a single malformed HTTP request without any race conditions or special prerequisites. Privileges Required (PR:N) is none, making this a fully unauthenticated attack. User Interaction (UI:N) is none, enabling automated exploitation.
The Scope (S:C) is changed, which is significant because it indicates that the denial of service impacts extend beyond the vulnerable ASA/FTD appliance to all network services that depend on it. When the perimeter firewall or VPN concentrator reloads, all protected network segments lose connectivity, VPN tunnels drop, and remote workers are disconnected. Confidentiality (C:N) and Integrity (I:N) are not directly affected, while Availability (A:H) is rated high. The affected versions span the same massive range as CVE-2024-20359, covering Cisco ASA 9.8.x through 9.20.x and FTD 6.2.3 through 7.4.1.
Frequently Asked Questions
What is CVE-2024-20353?
CVE-2024-20353 is a denial of service vulnerability in the management and VPN web servers of Cisco ASA and FTD software. An unauthenticated remote attacker can crash the device by sending a specially crafted HTTP request, causing all network traffic through the appliance to be interrupted.
How is CVE-2024-20353 related to the ArcaneDoor campaign?
CVE-2024-20353 is one of two vulnerabilities exploited in the ArcaneDoor state-sponsored espionage campaign, alongside CVE-2024-20359. In the campaign context, the denial of service capability may be used to force device reboots that trigger the execution of persistent backdoors installed through CVE-2024-20359.
Can this vulnerability be exploited without authentication?
Yes. The vulnerability requires no authentication and no user interaction. Any attacker who can send HTTP requests to the ASA/FTD management interface or VPN web portal can exploit this vulnerability to cause a device reload.
What happens when the device is exploited?
The Cisco ASA or FTD device crashes and reloads, which typically takes several minutes. During this time, all network traffic protected by the device is interrupted, all VPN tunnels are disconnected, and all management sessions are terminated. If the attacker repeatedly sends exploit requests, they can maintain a persistent denial of service condition.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.