{"cveID":"CVE-2024-20353","vendorProject":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","vulnerabilityName":"Cisco ASA and FTD Denial of Service Vulnerability","dateAdded":"2024-04-24","shortDescription":"Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2024-05-01","knownRansomwareCampaignUse":"Unknown","notes":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2;   https://nvd.nist.gov/vuln/detail/CVE-2024-20353","cwes":["CWE-835"],"year":2024,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2024-20353","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"dos","comments":"This vulnerability is exploited by a remote, unauthenticated attacker by sending a crafted HTTP request to a vulnerable device's web server. This exploitation is possible due to incomplete error checking when parsing HTTP headers. If successfully exploited, it can cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. In early 2024, the Cisco Product Security Incident Response Team (PSIRT) identified an attack campaign named ArcaneDoor, which targeted these vulnerabilities to implant malware, execute commands, and potentially exfiltrate data from compromised devices. ","references":["https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/","https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_attacks_event_response"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2024-20353","technique":"T1037","technique_name_at_mapping":"Boot or Logon Initialization Scripts","mapping_type":"secondary_impact","capability_group":"dos","comments":"This vulnerability is exploited by a remote, unauthenticated attacker by sending a crafted HTTP request to a vulnerable device's web server. This exploitation is possible due to incomplete error checking when parsing HTTP headers. If successfully exploited, it can cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is associated with an attack campaign named ArcaneDoor in early 2024. This campaign targeted this vulnerability among others to implant malware, execute commands, and potentially exfiltrate data from compromised devices. ","references":["https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/","https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_attacks_event_response"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2024-20353","technique":"T1608.001","technique_name_at_mapping":"Upload Malware","mapping_type":"secondary_impact","capability_group":"dos","comments":"This vulnerability is exploited by a remote, unauthenticated attacker by sending a crafted HTTP request to a vulnerable device's web server. This exploitation is possible due to incomplete error checking when parsing HTTP headers. If successfully exploited, it can cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is associated with an attack campaign named ArcaneDoor in early 2024. This campaign targeted this vulnerability among others to implant malware, execute commands, and potentially exfiltrate data from compromised devices. ","references":["https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/","https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_attacks_event_response"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2024-20353","technique":"T1653","technique_name_at_mapping":"Power Settings","mapping_type":"primary_impact","capability_group":"dos","comments":"This vulnerability is exploited by a remote, unauthenticated attacker by sending a crafted HTTP request to a vulnerable device's web server. This exploitation is possible due to incomplete error checking when parsing HTTP headers. If successfully exploited, it can cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is associated with an attack campaign named ArcaneDoor in early 2024. This campaign targeted this vulnerability among others to implant malware, execute commands, and potentially exfiltrate data from compromised devices. ","references":["https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/","https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_attacks_event_response"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1037","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Boot or Logon Initialization Scripts","name_at_mapping":"Boot or Logon Initialization Scripts","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":0,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true},{"id":"T1608.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Upload Malware","name_at_mapping":"Upload Malware","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":0,"has_detection_strategy":true},{"id":"T1653","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Power Settings","name_at_mapping":"Power Settings","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":1,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"partial","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}