CVE-2024-20358

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Apr 24, 2024
Updated: Apr 30, 2024
CWE ID 78

Summary

CVE-2024-20358 is a vulnerability affecting the Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software. An authenticated, local attacker with administrator privileges can exploit this issue by restoring a maliciously crafted backup file. The vulnerability arises due to improper sanitization of the backup file's contents during restoration. Successful exploitation allows the attacker to execute arbitrary commands with root-level privileges on the underlying Linux operating system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Adaptive Security Appliance ASA Software
  • Cisco Firepower Threat Defense Software
  • Cisco Firepower Threat Defense

Affected Vendors

  • Cisco Systems Inc