Infinite loop in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2024-20353

 

Infinite loop in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2024-20353

Published: April 24, 2024 / Updated: April 25, 2024


Vulnerability identifier: #VU88981
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20353
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop when parsing HTTP headers. A remote attacker can send specially crafted HTTP request to the appliance and perform a denial of service (DoS) attack.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)

How to mitigate CVE-2024-20353

Install updates from vendor's website.

Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.4.57, 9.18.4.22, 9.19.1.28, 9.20.2.10
Cisco Firewall Threat Defense (FTD) - addressed in versions 9.16.4.57, 9.18.4.22, 9.19.1.28, 9.20.2.10

External References

Related Security Bulletins