Code Injection in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2024-20485

 

Code Injection in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2024-20485

Published: October 24, 2024


Vulnerability identifier: #VU99312
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20485
CWE-ID: CWE-94
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper validation of a specific file when it is read from system flash memory in the VPN web server. A local user can restore a specially crafted backup file on the affected device and execute arbitrary code with elevated privileges.


Affected software

Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)

How to mitigate CVE-2024-20485

Install updates from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 7.0.6.3, 7.2.9, 7.4.2, 7.6.0
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.4.61, 9.17.1.45, 9.18.4.24, 9.19.1.28, 9.20.2.21, 9.22.1.1

External References

Related Security Bulletins