FAIL › dossier
Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
PRODUCT· dossier confidence 50%
Cisco ASA/FTD devices have a concerning history of exploitable vulnerabilities, demonstrating a potential weakness in their security posture. These recurring issues, often exploited in active attacks, necessitate immediate attention and remediation to mitigate risk. The presence of zero-day exploits and privilege escalation vulnerabilities highlights a critical need for enhanced security controls.
Cisco ASA/FTD devices have a history of critical and high-severity vulnerabilities, including remote code execution, cross-site scripting, and denial-of-service attacks. These vulnerabilities have been actively exploited in the wild, often linked to ransomware attacks, indicating a need for improved patching and security practices.
- Memory disclosure via URL parsing
- XSS vulnerability linked to ransomware
- Improper input validation vulnerability
- Remote DoS attack
- Local privilege escalation to root
- Infinite loop DoS bug
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-02-15 | CVE-2020-3259 | critical | Cisco ASA/FTD memory disclosure flaw leaked secrets via invalid URL parsing in specific AnyConnect/WebVPN setups. |
| 2021-11-03 | CVE-2020-3580 | critical | Cisco ASA/FTD devices were vulnerable to XSS, actively exploited and linked to ransomware attacks. |
| 2021-11-03 | CVE-2020-3452 | high | Cisco ASA and FTD devices suffered a path traversal flaw allowing attackers to read arbitrary files via crafted HTTP requests. |
| 2024-10-24 | CVE-2024-20481 | high | Cisco ASA/FTD devices are vulnerable to remote DoS attacks via CVE-2024-20481, which is actively exploited in the wild. |
| 2024-04-24 | CVE-2024-20359 | high | Cisco ASA/FTD devices allow local privilege escalation from Administrator to root via CVE-2024-20359, enabling attackers to bypass admin controls and gain full system access. |
| 2024-04-24 | CVE-2024-20353 | high | Cisco ASA/FTD devices are vulnerable to remote DoS via an infinite loop bug, currently in CISA KEV. |