KEVIntel
8.6
CVSS
High

CVE-2024-20353

PUBLISHED

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)...

Exploited in the wild Remote Low complexity No user interaction
Vendor
Cisco
Product
Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software
Published
Apr 24, 2024
EPSS

Description

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.

cisa edge nessus_scanner

CVSS scores

CVSS v3.1 8.6 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Exploitation status

Exploited in the wild

Recorded 2024-04-24 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Apr 24, 2024

Scanner integrations

Scanner Reference Detected
Nessus https://www.tenable.com/plugins/nessus/193915 Jun 02, 2025

Timeline

  • CVE ID Reserved

  • Added to KEVIntel

  • CVE Published to Public

  • Detected by Nessus