LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-20359: Cisco ASA and FTD Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 24, 2024
CVSS 6.0 · Medium⚠ Actively exploited (CISA KEV)
6.0
CVSS score
Medium
Severity
Active
CISA KEV
No
Ransomware use
May 1, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-20359 to its Known Exploited Vulnerabilities catalog on Apr 24, 2024, with a federal patch deadline of May 1, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This vulnerability is due to improper validation of a file when it is read from system flash memory. An attacker could exploit this vulnerability by copying a crafted file to the disk0: file system of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the affected device after the next reload of the device, which could alter system behavior. Because the injected code could persist across device reboots, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.

CVE-2024-20359 is a privilege escalation vulnerability in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. It allows a local attacker who already has Administrator privileges to escalate to root. This matters because ASA and FTD devices commonly sit at network perimeters or enforce security policy; full root control can let an attacker disable protections, alter configurations, or pivot further into the environment. Confirm exact impact and scope against the vendor advisory.

CISA notes that organizations should apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Public detail on exploitation mechanics is limited; treat any local Administrator access as a high-risk foothold until remediated.

How it works

The vulnerability is classified under CWE-94 (Improper Control of Generation of Code, also known as code injection). In products of this class, insufficient validation or sanitization of inputs that influence code generation or execution can allow an attacker to inject and run unintended code or commands.

According to the CISA summary, an attacker with local Administrator access on a vulnerable ASA or FTD device can abuse the flaw to escalate privileges to root. Root access typically grants unrestricted control over the device, including the ability to modify system files, install persistent components, or alter traffic handling. Specific exploit steps, required inputs, or exact conditions are not provided in the available facts and must be confirmed against the vendor advisory; do not assume remote exploitation is possible without additional local access.

Am I affected? How to find it in your systems

Cisco ASA and FTD appliances are typically deployed as firewalls, VPN gateways, or next-generation firewalls at network edges, data-center perimeters, or in virtual form on hypervisors. Inventory every ASA and FTD instance, including physical appliances, virtual machines, and any high-availability pairs or clusters.

If your environment uses centralized logging or SIEM rules for Cisco devices, ensure those feeds capture authentication, privilege, and configuration events so you can hunt for signs of local abuse.

How to remediate

Patch first. Apply the vendor-supplied software update that addresses CVE-2024-20359 as described in the official Cisco advisory. Follow the vendor’s upgrade path, including any required intermediate releases or reboot procedures, and validate the new version after installation.

CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Confirm all steps against the vendor advisory before declaring the environment remediated.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface and increase detection.

These controls do not eliminate the vulnerability but can lower the likelihood of successful local escalation and improve the chance of detecting abuse. Plan to apply the official patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities on network devices can lead to broader compromise, including configuration theft, credential harvesting, or lateral movement that ultimately exposes data. Known ransomware use of this specific CVE is not documented in the available facts. If you suspect the device was compromised, isolate it, preserve forensic evidence, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data sets to check whether related credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
WeaknessCWE-94
CVSS base score6.0 (Medium)
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
PublishedApr 24, 2024
Added to CISA KEVApr 24, 2024
Federal patch deadlineMay 1, 2024
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities