EXPOSURES › CVE-2024-20353
CVE-2024-20353
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco ASA/FTD devices are vulnerable to remote DoS via an infinite loop bug, currently in CISA KEV.
The infinite loop vulnerability allows remote denial of service, potentially disrupting critical network infrastructure for DIB organizations. Immediate patching is required to prevent service disruption and maintain FedRAMP/NIST 800-171 availability controls.
Shame score — A remote DoS vulnerability is serious but less critical than RCE or data breaches, though it still impacts availability.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |