OS Command Injection in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2024-20358
Published: April 24, 2024
Vulnerability identifier: #VU88979
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20358
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper validation of a backup file contents when restoring the system. A local user can pass a specially crafted file and execute arbitrary OS commands with root privileges.
Affected software
Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)
Cisco Firewall Threat Defense (FTD)
How to mitigate CVE-2024-20358
Install updates from vendor's website.
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.4.57, 9.18.4.22, 9.19.1.28, 9.20.2.10
Cisco Firewall Threat Defense (FTD) - addressed in versions 9.16.4.57, 9.18.4.22, 9.19.1.28, 9.20.2.10
Cisco Firewall Threat Defense (FTD) - addressed in versions 9.16.4.57, 9.18.4.22, 9.19.1.28, 9.20.2.10