← Vulnerability feed

Vulnerability record · CVE-2024-20353 · published 24 April 2024

CVE-2024-20353: Cisco ASA and FTD web server HTTP header parsing DoS

Cisco · Adaptive Security Appliance Software

Cisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload the device. Because the affected interfaces are internet-facing on many deployments, an unauthenticated remote attacker can repeatedly force outages.

8.6 CVSS 3.1 High CISA KEV since 24 Apr 2024 EPSS 71% · top 0.6% CWE-835 · CWE-835
8.6CVSS 3.1 base score
71%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
4References, 1 tagged exploit
11 Aug 2026Last modified by NVD

Description

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityUnauthenticated remote denial of service on perimeter security devices, listed in KEV with very high EPSS, though impact is availability only.

What it is

Cisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload the device. Because the affected interfaces are internet-facing on many deployments, an unauthenticated remote attacker can repeatedly force outages.

Impact

An attacker gains the ability to cause a denial of service by forcing the device to reload, disrupting VPN and management access for all users of that appliance. No data confidentiality or integrity impact is described.

Attack surface

Reachable over the network via a crafted HTTP request to the management or VPN web server; the CVSS vector shows no privileges or user interaction required. Any device with those web services exposed is a candidate target.

Exploitation

CVE-2024-20353 is listed in CISA KEV with a 2024-05-01 remediation due date, and a third-party advisory reference is tagged Exploit, indicating real-world exploitation. EPSS is very high at roughly 0.71 (99th percentile), consistent with active targeting.

What to do

  • Apply the Cisco vendor advisory fixes for ASA and FTD software as the first action.
  • If patching cannot be done immediately, follow Cisco's instructions to disable or restrict the affected management and VPN web services, or discontinue use per CISA guidance.
  • Restrict HTTP/HTTPS access to the management and VPN web servers to trusted management networks only.
  • Monitor for unexpected device reloads and correlate them with inbound HTTP traffic to those interfaces.
  • Track the CISA KEV due date and confirm remediation before it passes.

Detection

  • Alert on ASA/FTD syslog messages indicating unexpected reloads or crashes and correlate with inbound HTTP requests.
  • Review web server access logs on the appliance for malformed or anomalous HTTP headers targeting management/VPN interfaces.
  • Monitor for repeated connection attempts or request floods against the management and VPN web services from single sources.
  • Baseline normal reload events and investigate any reload without a change ticket or maintenance window.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-20353 to the Known Exploited Vulnerabilities catalog on 24 April 2024 as "Cisco ASA and FTD Denial of Service Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 1 May 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-20353 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-20353), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.