#VU99322 Permissions, Privileges, and Access Controls in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2024-20370

 

#VU99322 Permissions, Privileges, and Access Controls in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2024-20370

Published: October 24, 2024


Vulnerability identifier: #VU99322
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-20370
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a local administrator to escalate privileges on the system.

The vulnerability exists due to insecure storage and permissions within certain system configurations and executable files, which leads to security restrictions bypass and privilege escalation.


Remediation

Install updates from vendor's website.

External links