CVEs
CVE-2024-20353
High · 8.6KEVCWE-835Source: NVD
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.
CVSS 3.1 8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Published 4/24/2024
Indicators of compromise
No indicators of compromise recorded. Run AI enrichment to research IOCs.
CISA KEV
Added 2024-04-24
Remediation due 2024-05-01
Ransomware use: Unknown
EPSS
71%
Probability of exploitation in the next 30 days.
Affected products
- Cisco Catalyst 9300Excluded
Public exploits / PoCs
No public PoC repositories found.