CVE-2024-20353Wednesday, February 18, 2026

Cisco ASA/FTD Web Services Denial of Service Vulnerability

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

Not KEV Listed✓ Fix Available
Cisco ASA/FTD Web Services Denial of Service Vulnerability
💡

This section explains the vulnerability in everyday language, so anyone can understand the risk and impact.

This security flaw affects Cisco's popular firewall products (ASA and FTD). When these devices have their web interface enabled, an attacker from the internet can send specially crafted network requests that could crash the device or make it stop working properly. This doesn't give the attacker control of the firewall, but it could disrupt network operations and require the device to be restarted.

The vulnerability has gained attention as part of the 'ArcaneDoor' campaign, where attackers are actively trying to exploit this and similar weaknesses in Cisco devices. This is particularly concerning because these firewalls are often used by large organizations to protect their networks.

Affected Products

2affected products identified
ProductVendorVersionPatched
>Adaptive Security Appliance (ASA) SoftwareCisco9.4 and laterVaries by release track
>Firepower Threat Defense (FTD) SoftwareCisco6.4 and laterVaries by release track
🔧

Remediation

Fix Available

1. Upgrade to the latest ASA or FTD software version that includes the security fix

2. If immediate upgrade is not possible, disable the web services interface if not required

3. Implement access control lists (ACLs) to restrict access to the web services interface to trusted IP addresses only

4. Monitor for suspicious activity targeting the web interface

🔗

Sources & References

CVSS Score
7.5
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Vector (v3.1)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Quick Info
CVE IDCVE-2024-20353
Severityhigh
FixAvailable
KEVNot Listed
PublishedFeb 18, 2026