
CVE-2024-20359 is a persistent remote code execution vulnerability in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) when handling VPN web server requests. Attackers can survive reboots on unpatched appliances — a critical risk for perimeter VPN concentrators.
Affected Cisco releases
- ASA 9.12 through 9.16 before vendor fix
- FTD 7.0 through 7.4 before fixed maintenance release
- Remote Access VPN and SSL VPN portals exposed to the internet
Verify firmware
show version | include Software
show running-config | include webvpnRemediation
- Apply Cisco PSIRT fixed ASA/FTD image from advisory
- Disable webvpn temporarily if emergency patch window is needed
- Restrict VPN portal source IPs at upstream firewall
- Inspect for unknown local users, cron, and modified
disk0:files post-patch
CISA KEV. Treat unpatched Cisco VPN gateways as actively targeted.