VYPR
Unrated severityCISA KEVNVD Advisory· Published Apr 24, 2024· Updated Oct 21, 2025

CVE-2024-20353

CVE-2024-20353

Description

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.

Affected products

2
  • Cisco/Cisco Adaptive Security Appliance (ASA) Softwarev5
    Range: 9.8.1
  • Cisco/Cisco Firepower Threat Defense Softwarev5
    Range: 6.2.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.