Hack The Sec - Leading Resource Of Linux Tutorial
Cisco ASA and FTD VPN Persistent RCE (CVE-2024-20359)

Cisco ASA and FTD VPN Persistent RCE (CVE-2024-20359)

Cisco ASA software version check for CVE-2024-20359

CVE-2024-20359 is a persistent remote code execution vulnerability in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) when handling VPN web server requests. Attackers can survive reboots on unpatched appliances — a critical risk for perimeter VPN concentrators.

Affected Cisco releases

  • ASA 9.12 through 9.16 before vendor fix
  • FTD 7.0 through 7.4 before fixed maintenance release
  • Remote Access VPN and SSL VPN portals exposed to the internet

Verify firmware

show version | include Software
show running-config | include webvpn

Remediation

  • Apply Cisco PSIRT fixed ASA/FTD image from advisory
  • Disable webvpn temporarily if emergency patch window is needed
  • Restrict VPN portal source IPs at upstream firewall
  • Inspect for unknown local users, cron, and modified disk0: files post-patch

CISA KEV. Treat unpatched Cisco VPN gateways as actively targeted.

H

About the author

I am a Linux Administrator and Security Expert. Through this site I share Linux tutorials, hardening guides and security news.

Comments