Improper Neutralization of Expression/Command Delimiters in Cisco Adaptive Security Appliance (ASA) - CVE-2024-20329

 

Improper Neutralization of Expression/Command Delimiters in Cisco Adaptive Security Appliance (ASA) - CVE-2024-20329

Published: October 25, 2024


Vulnerability identifier: #VU99334
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20329
CWE-ID: CWE-146
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute operating system commands as root.

The vulnerability exists due to insufficient validation of user input in the SSH subsystem. A remote user can execute arbitrary commands on the underlying operating system with elevated privileges.


Affected software

Cisco Adaptive Security Appliance (ASA)

How to mitigate CVE-2024-20329

Install updates from vendor's website.

Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.17.1.39, 9.17.1.45, 9.18.4, 9.18.4.5, 9.18.4.8, 9.18.4.22, 9.18.4.24, 9.18.4.29, 9.18.4.34, 9.18.4.40, 9.18.4.47, 9.19.1.22, 9.19.1.24, 9.19.1.27, 9.19.1.28, 9.19.1.31, 9.19.1.37, 9.20.1, 9.20.1.5, 9.20.2, 9.20.2.10, 9.20.2.21, 9.20.2.22, 9.20.3, 9.20.3.4, 9.20.3.7, 9.22.1.1

External References

Related Security Bulletins