CVE-2024-20359

MEDIUM(6.0)KEVElevated Risk

Cisco ASA and FTD Privilege Escalation Vulnerability

Description

CVE-2024-20359 is a medium-severity persistent code execution vulnerability in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software that exploits a legacy VPN client and plug-in preloading capability. An authenticated local attacker with administrator-level privileges can execute arbitrary code with root-level privileges by exploiting this feature. With a CVSS v3.1 base score of 6.0, the vulnerability has a limited attack surface due to the requirement for administrator access, but its impact is amplified by the persistence mechanism that survives device reboots. CISA has added CVE-2024-20359 to the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of May 1, 2024, and its association with the sophisticated ArcaneDoor espionage campaign makes it a high-priority concern despite its moderate CVSS score.

KEV Information

Vendor
Cisco
Product
Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Date Added
April 24, 2024
Due Date
May 1, 2024
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
0.8
Impact Score
5.2

CWEs

Affected Products

VendorProductVersion
ciscoadaptive security appliance software9.8.1; 9.8.1.5; 9.8.1.7; 9.8.2; 9.8.2.8; 9.8.2.14; 9.8.2.15; 9.8.2.17; 9.8.2.20; 9.8.2.24; 9.8.2.26; 9.8.2.28; 9.8.2.33; 9.8.2.35; 9.8.2.38; 9.8.3; 9.8.3.8; 9.8.3.11; 9.8.3.14; 9.8.3.16; 9.8.3.18; 9.8.3.21; 9.8.3.26; 9.8.3.29; 9.8.4; 9.8.4.3; 9.8.4.7; 9.8.4.8; 9.8.4.10; 9.8.4.12; 9.8.4.15; 9.8.4.17; 9.8.4.20; 9.8.4.22; 9.8.4.25; 9.8.4.26; 9.8.4.29; 9.8.4.32; 9.8.4.33; 9.8.4.34; 9.8.4.35; 9.8.4.39; 9.8.4.40; 9.8.4.41; 9.8.4.43; 9.8.4.44; 9.8.4.45; 9.8.4.46; 9.8.4.48; 9.12.1; 9.12.1.2; 9.12.1.3; 9.12.2; 9.12.2.1; 9.12.2.4; 9.12.2.5; 9.12.2.9; 9.12.3; 9.12.3.2; 9.12.3.7; 9.12.3.9; 9.12.3.12; 9.12.4; 9.12.4.2; 9.12.4.4; 9.12.4.7; 9.12.4.8; 9.12.4.10; 9.12.4.13; 9.12.4.18; 9.12.4.24; 9.12.4.26; 9.12.4.29; 9.12.4.30; 9.12.4.35; 9.12.4.37; 9.12.4.38; 9.12.4.39; 9.12.4.40; 9.12.4.41; 9.12.4.47; 9.12.4.48; 9.12.4.50; 9.12.4.52; 9.12.4.54; 9.12.4.55; 9.12.4.56; 9.12.4.58; 9.12.4.62; 9.12.4.65; 9.14.1; 9.14.1.6; 9.14.1.10; 9.14.1.15; 9.14.1.19; 9.14.1.30; 9.14.2; 9.14.2.4; 9.14.2.8; 9.14.2.13; 9.14.2.15; 9.14.3; 9.14.3.1; 9.14.3.9; 9.14.3.11; 9.14.3.13; 9.14.3.15; 9.14.3.18; 9.14.4; 9.14.4.6; 9.14.4.7; 9.14.4.12; 9.14.4.13; 9.14.4.14; 9.14.4.15; 9.14.4.17; 9.14.4.22; 9.14.4.23; 9.15.1; 9.15.1.1; 9.15.1.7; 9.15.1.10; 9.15.1.15; 9.15.1.16; 9.15.1.17; 9.15.1.21; 9.16.1; 9.16.1.28; 9.16.2; 9.16.2.3; 9.16.2.7; 9.16.2.11; 9.16.2.13; 9.16.2.14; 9.16.3; 9.16.3.3; 9.16.3.14; 9.16.3.15; 9.16.3.19; 9.16.3.23; 9.16.4; 9.16.4.9; 9.16.4.14; 9.16.4.18; 9.16.4.19; 9.16.4.27; 9.16.4.38; 9.16.4.39; 9.16.4.42; 9.16.4.48; 9.16.4.55; 9.17.1; 9.17.1.7; 9.17.1.9; 9.17.1.10; 9.17.1.11; 9.17.1.13; 9.17.1.15; 9.17.1.20; 9.17.1.30; 9.17.1.33; 9.18.1; 9.18.1.3; 9.18.2; 9.18.2.5; 9.18.2.7; 9.18.2.8; 9.18.3; 9.18.3.39; 9.18.3.46; 9.18.3.53; 9.18.3.55; 9.18.3.56; 9.18.4; 9.18.4.5; 9.18.4.8; 9.19.1; 9.19.1.5; 9.19.1.9; 9.19.1.12; 9.19.1.18; 9.19.1.22; 9.19.1.24; 9.19.1.27; 9.20.1; 9.20.1.5; 9.20.2
ciscosecure firewall threat defense6.2.3; 6.2.3.1; 6.2.3.2; 6.2.3.3; 6.2.3.4; 6.2.3.5; 6.2.3.6; 6.2.3.7; 6.2.3.8; 6.2.3.9; 6.2.3.10; 6.2.3.11; 6.2.3.12; 6.2.3.13; 6.2.3.14; 6.2.3.15; 6.2.3.16; 6.2.3.17; 6.2.3.18; 6.4.0; 6.4.0.1; 6.4.0.2; 6.4.0.3; 6.4.0.4; 6.4.0.5; 6.4.0.6; 6.4.0.7; 6.4.0.8; 6.4.0.9; 6.4.0.10; 6.4.0.11; 6.4.0.12; 6.4.0.13; 6.4.0.14; 6.4.0.15; 6.4.0.16; 6.4.0.17; 6.6.0; 6.6.0.1; 6.6.1; 6.6.3; 6.6.4; 6.6.5; 6.6.5.1; 6.6.5.2; 6.6.7; 6.6.7.1; 6.7.0; 6.7.0.1; 6.7.0.2; 6.7.0.3; 7.0.0; 7.0.0.1; 7.0.1; 7.0.1.1; 7.0.2; 7.0.2.1; 7.0.3; 7.0.4; 7.0.5; 7.0.6; 7.0.6.1; 7.1.0; 7.1.0.1; 7.1.0.2; 7.1.0.3; 7.2.0; 7.2.0.1; 7.2.1; 7.2.2; 7.2.3; 7.2.4; 7.2.4.1; 7.2.5; 7.2.5.1; 7.3.0; 7.3.1; 7.3.1.1; 7.4.0; 7.4.1

Multiple CVSS Assessments

Source: [email protected](Secondary)
6.0
MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Source: [email protected](Primary)
6.0
MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

References

Weakness Type

Legacy Preloading Capability Abuse

CVE-2024-20359 exploits a legacy capability in Cisco ASA and FTD software that was designed to allow administrators to preload VPN clients and plug-ins onto the security appliance. This feature, which loads arbitrary code packages during the device boot process, lacks sufficient validation of the code being loaded, allowing an attacker with administrator access to inject malicious code that executes with root privileges and persists across device reboots. This weakness is related to CWE-94 (Improper Control of Generation of Code), where the system fails to properly restrict what code can be loaded and executed through the preloading mechanism, and CWE-269 (Improper Privilege Management), where the elevated execution context of the preloaded code enables privilege escalation beyond the administrator's intended capabilities. Learn more about CWE-269

Impact Analysis

The impact of CVE-2024-20359 is concentrated on confidentiality and integrity, both rated high, while availability is not directly affected. Confidentiality is fully compromised because root-level code execution on a perimeter security appliance provides the attacker with access to all network traffic passing through the device, VPN session data, decrypted traffic flows, authentication credentials, firewall rule configurations, and any stored certificates or keys. For organizations relying on ASA or FTD as their primary perimeter defense, this represents exposure of virtually all network communications.

Integrity faces high impact because the persistent root-level access allows the attacker to modify firewall rules to permit unauthorized traffic, alter VPN configurations to enable covert access, inject network traffic, modify logging to conceal their activities, and install additional backdoors. The persistence mechanism means that the malicious code survives reboots, making it extremely difficult to detect and remove through normal operational procedures.

Availability is rated as unaffected (A:N) in the CVSS vector because the exploitation does not inherently disrupt device operations. However, the practical availability risk is significant if the attacker chooses to disable security features or disrupt network connectivity. The attack requires local access (AV:L) with high privileges (PR:H) and no user interaction (UI:N). The EPSS score of 0.22% at the 44.4th percentile is relatively low, reflecting the requirement for pre-existing administrator access, but the confirmed use in the ArcaneDoor espionage campaign demonstrates that sophisticated threat actors have operationalized this vulnerability. CISA classifies the ransomware association as "Unknown."

Exploit Maturity

CVE-2024-20359 has been confirmed as actively exploited in the wild as part of the sophisticated ArcaneDoor espionage campaign documented by Cisco Talos Intelligence. The ArcaneDoor campaign is a state-sponsored espionage operation specifically targeting perimeter network devices, including Cisco ASA firewalls, to establish persistent access into targeted organizations' networks.

Cisco disclosed the vulnerability through security advisory cisco-sa-asaftd-persist-rce-FLsNXF4h, confirming that the vulnerability was discovered during investigation of the ArcaneDoor attacks. Despite the relatively low EPSS score of 0.22% at the 44.4th percentile, which reflects the high privilege requirement rather than low threat level, the exploitation by a sophisticated threat actor demonstrates that the vulnerability is being used in targeted campaigns against high-value targets. The requirement for administrator-level access does not diminish the severity in environments where attackers may obtain credentials through phishing, credential stuffing, or exploitation of other vulnerabilities. CISA classifies the ransomware association as "Unknown," and the vulnerability's primary use case appears to be long-term espionage rather than financial crime.

Remediation

  1. Apply Cisco security updates immediately by upgrading Cisco ASA and FTD software to a fixed version as specified in Cisco's security advisory. Given the association with state-sponsored espionage, this should be treated as a critical priority even though the CVSS score is medium.

  2. Verify device integrity by examining the ASA or FTD device for signs of compromise before and after patching. Follow Cisco's integrity verification procedures to check for unauthorized preloaded VPN client packages, modified system images, or unexpected files in the device's flash storage. Compare running configurations against known-good baselines.

  3. Audit administrator account access to identify any unauthorized or unnecessary administrator accounts on ASA and FTD devices. Implement multi-factor authentication for all administrative access, enforce strong password policies, and review authentication logs for suspicious login activity from unexpected sources.

  4. Disable the legacy VPN client preloading capability if it is not required for your organization's operations. Since this is a legacy feature, many modern deployments can operate without it, eliminating the attack vector entirely.

  5. Implement network monitoring for perimeter devices by deploying detection capabilities specifically designed to identify anomalous behavior on security appliances. Monitor for unexpected outbound connections from the ASA/FTD, unusual traffic patterns, changes to device configurations, and indicators associated with the ArcaneDoor campaign as documented by Cisco Talos.

Technical Details

CVE-2024-20359 is a persistent code execution vulnerability in Cisco ASA and FTD Software. The CVSS v3.1 vector is CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N, resulting in a base score of 6.0 (Medium).

The vulnerability resides in a legacy capability within Cisco ASA and FTD software that enables administrators to preload VPN client packages and plug-ins onto the device. This feature was designed to allow the security appliance to distribute VPN client software to connecting users. The preloaded packages are stored in the device's persistent storage and loaded during the boot process, executing with root-level privileges as part of the system initialization.

The flaw is that the preloading mechanism does not sufficiently validate the integrity or authenticity of the code being loaded. An attacker who has obtained administrator-level access to the device can upload a malicious package that masquerades as a legitimate VPN client or plug-in. This package is then persistently stored and automatically executed with root privileges during every subsequent boot, establishing a persistent backdoor that survives device reboots, software upgrades (in some cases), and configuration resets.

The Attack Vector (AV:L) indicates that the attacker needs local access to the device, which in the context of network appliances typically means access through the management interface (SSH, HTTPS console, or serial connection). Attack Complexity (AC:L) is low because the preloading mechanism is a documented feature. Privileges Required (PR:H) is high, requiring administrator-level credentials. User Interaction (UI:N) is none, as the exploit can be executed through administrative commands without additional user action. The Scope (S:U) is unchanged. Confidentiality (C:H) and Integrity (I:H) are both rated high because root-level access on a perimeter firewall compromises all traffic and configurations, while Availability (A:N) is not directly affected. The affected versions span a massive range of Cisco ASA (9.8.x through 9.20.x) and FTD (6.2.3 through 7.4.1) releases.

Frequently Asked Questions

What is CVE-2024-20359?

CVE-2024-20359 is a persistent code execution vulnerability in Cisco ASA and FTD software that allows an authenticated administrator to execute arbitrary code with root privileges by abusing a legacy VPN client preloading capability. The malicious code persists across device reboots.

What is the ArcaneDoor campaign?

ArcaneDoor is a sophisticated state-sponsored espionage campaign that targeted perimeter network devices, specifically Cisco ASA firewalls. The campaign was discovered by Cisco Talos and involved the exploitation of CVE-2024-20359 along with other vulnerabilities to establish persistent access to targeted networks.

Does this vulnerability require administrator access?

Yes. Exploitation requires administrator-level privileges on the Cisco ASA or FTD device. However, attackers may obtain these credentials through phishing, credential reuse, or exploitation of other vulnerabilities, so the privilege requirement should not diminish the urgency of patching.

How can I check if my device has been compromised?

Follow Cisco's integrity verification procedures to examine your ASA or FTD device for unauthorized preloaded packages, modified system images, or unexpected files. Review the Cisco Talos ArcaneDoor blog post for specific indicators of compromise and detection guidance.

CVSS Score

6.0
MEDIUM(6.0)

EPSS Score

EPSS Score19.43%
EPSS Percentile97.1%

Dates

PublishedApril 24, 2024
Last ModifiedAugust 11, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.