Skip to content
COOEY

EXPOSURES › CVE-2024-20353

CVE-2024-20353

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-04-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-20353 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatched

Cisco ASA/FTD devices are vulnerable to remote DoS via an infinite loop bug, currently in CISA KEV.

The infinite loop vulnerability allows remote denial of service, potentially disrupting critical network infrastructure for DIB organizations. Immediate patching is required to prevent service disruption and maintain FedRAMP/NIST 800-171 availability controls.

Shame score — A remote DoS vulnerability is serious but less critical than RCE or data breaches, though it still impacts availability.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized