← Vulnerability feed

Vulnerability record · CVE-2024-20359 · published 24 April 2024

CVE-2024-20359: Cisco ASA and FTD persistent code injection via crafted file preload

Cisco · Adaptive Security Appliance Software

Cisco ASA and FTD software fail to properly validate a file read from system flash memory in a legacy VPN client/plug-in preloading capability. An authenticated local attacker with administrator-level privileges can copy a crafted file to disk0: and achieve root-level code execution after the next device reload. Because the injected code persists across reboots, Cisco raised the advisory's Security Impact Rating from Medium to High.

6.0 CVSS 3.1 Medium CISA KEV since 24 Apr 2024 EPSS 19% · top 2.7% CWE-94 · Code injection
6.0CVSS 3.1 base score
19%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
4References, 1 tagged exploit
11 Aug 2026Last modified by NVD

Description

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This vulnerability is due to improper validation of a file when it is read from system flash memory. An attacker could exploit this vulnerability by copying a crafted file to the disk0: file system of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the affected device after the next reload of the device, which could alter system behavior. Because the injected code could persist across device reboots, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is in CISA's KEV catalog with confirmed exploitation in the ArcaneDoor campaign and yields persistent root-level code execution, though it requires local administrator privileges.

What it is

Cisco ASA and FTD software fail to properly validate a file read from system flash memory in a legacy VPN client/plug-in preloading capability. An authenticated local attacker with administrator-level privileges can copy a crafted file to disk0: and achieve root-level code execution after the next device reload. Because the injected code persists across reboots, Cisco raised the advisory's Security Impact Rating from Medium to High.

Impact

An attacker with administrator-level access gains root-level code execution on the affected device, allowing alteration of system behavior. The injected code persists across reboots, giving a durable foothold on perimeter network devices.

Attack surface

Reached locally by copying a crafted file to the disk0: file system; the CVSS vector (AV:L/PR:H/UI:N) indicates local access with high privileges required and no user interaction. Exploitation requires administrator-level privileges on the device.

Exploitation

CVE-2024-20359 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2024-04-24, due 2024-05-01), and a Cisco Talos reference is tagged as an exploit tied to the ArcaneDoor espionage campaign. EPSS gives a 30-day probability of 0.19434 (97.2nd percentile), indicating elevated likelihood.

What to do

  • Apply the Cisco vendor advisory patches for ASA and FTD software immediately.
  • If patching is not possible, apply the mitigations in the Cisco advisory or discontinue use of the affected product per CISA's required action.
  • Restrict administrator-level access to ASA and FTD devices to trusted personnel only.
  • Monitor and control writes to the disk0: file system on affected devices.
  • Review device configurations and flash contents for unexpected files or persistence mechanisms.

Detection

  • Monitor for unexpected or crafted files written to the disk0: file system on ASA and FTD devices.
  • Audit administrator-level account activity and local access to affected devices.
  • Inspect device flash contents and startup behavior for signs of injected code that persists across reloads.
  • Correlate device logs with known ArcaneDoor campaign indicators from the Cisco Talos advisory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-20359 to the Known Exploited Vulnerabilities catalog on 24 April 2024 as "Cisco ASA and FTD Privilege Escalation Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 1 May 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-20359 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2024-20359), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.