Executive Summary
In June 2024, CISA issued an urgent alert to federal agencies following the discovery of active exploitation of two critical vulnerabilities (CVE-2024-20353 and CVE-2024-20359) in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices. Threat actors leveraged these flaws to bypass authentication and remotely execute code, potentially enabling lateral movement and unauthorized network access. Several government and enterprise environments were left exposed due to unpatched systems, raising significant risk to sensitive operations and regulated data.
This incident underscores the growing sophistication of cybercriminals targeting network infrastructure, particularly edge devices, and highlights the urgent need for rapid patch management and network segmentation as threat vectors continually evolve.
Why This Matters Now
The exploitation of critical Cisco ASA and Firepower vulnerabilities puts federal agencies and enterprises at immediate risk of network compromise. With attackers actively targeting unpatched systems, organizations must prioritize vulnerability management, enforce network segmentation, and enhance monitoring to prevent large-scale breaches and regulatory fallout.
Attack Path Analysis
The attack began with exploitation of unpatched vulnerabilities in Cisco ASA and Firepower devices, allowing adversaries initial access into federal networks. Attackers then sought to escalate privileges by leveraging device misconfigurations or credential harvesting. Lateral movement followed, as the attackers pivoted within the internal network to access additional resources. Command & Control was established using covert communication channels to receive instructions and maintain persistence. Sensitive data was then exfiltrated through unauthorized outbound channels. Finally, the attackers could disrupt operations, deploy ransomware, or further degrade network integrity.
Kill Chain Progression
Initial Compromise
Description
Adversaries exploited actively unpatched CVEs in Cisco ASA/Firepower network devices to gain unauthorized entry to the cloud or hybrid environment perimeter.
Related CVEs
CVE-2018-0296
CVSS 7.5A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or view sensitive system information without authentication.
Affected Products:
Cisco Adaptive Security Appliance (ASA) – 9.4, 9.5, 9.6, 9.7, 9.8, 9.9, 9.10, 9.12
Cisco Firepower Threat Defense (FTD) – 6.2.2, 6.2.3, 6.3.0, 6.4.0
Exploit Status:
exploited in the wildCVE-2024-20353
CVSS 7.5A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
Affected Products:
Cisco Adaptive Security Appliance (ASA) – 9.16, 9.17, 9.18
Cisco Firepower Threat Defense (FTD) – 7.0, 7.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
External Remote Services
Exploitation of Remote Services
Command and Scripting Interpreter
Boot or Logon Autostart Execution
Impair Defenses
Network Service Discovery
Valid Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Patch Management and Vulnerability Identification
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Audit Trail
Control ID: 500.06
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Asset Management & Vulnerability Management
Control ID: Pillar 2.1
NIS2 Directive – Incident Prevention and Response
Control ID: Article 21(2)(c)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face critical exposure to actively exploited Cisco ASA/Firepower vulnerabilities requiring immediate patching of network infrastructure and zero trust segmentation implementation.
Financial Services
Banking institutions vulnerable to network infrastructure attacks targeting Cisco devices, risking encrypted traffic exposure and requiring enhanced egress security policy enforcement measures.
Health Care / Life Sciences
Healthcare networks using Cisco ASA devices face HIPAA compliance risks from unencrypted traffic exposure and lateral movement threats requiring immediate vulnerability remediation.
Defense/Space
Defense contractors with Cisco network appliances face critical security risks from actively exploited vulnerabilities potentially enabling threat detection evasion and data exfiltration.
Sources
- CISA warns feds to fully patch actively exploited Cisco flawshttps://www.bleepingcomputer.com/news/security/cisa-warns-feds-to-fully-patch-actively-exploited-cisco-flaws/Verified
- Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerabilityhttps://nvd.nist.gov/vuln/detail/CVE-2018-0296Verified
- Cisco ASA and FTD Denial of Service Vulnerabilityhttps://nvd.nist.gov/vuln/detail/CVE-2024-20353Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust Segmentation, inline threat detection, egress policy enforcement, and real-time visibility embodied by CNSF controls would have contained attacker movement, prevented unauthorized data exfiltration, and enabled early detection of abnormal behaviors at every stage of the kill chain.
Control: Inline IPS (Suricata)
Mitigation: Active exploitation attempts are detected and blocked at the perimeter.
Control: Zero Trust Segmentation
Mitigation: Limits scope of privilege escalation to only necessary network segments.
Control: East-West Traffic Security
Mitigation: Restricts and monitors all east-west communications, detecting anomalous movement.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks or flags unauthorized outbound connections commonly used for C2.
Control: Cloud Firewall (ACF) & Encrypted Traffic Enforcement
Mitigation: Prevents unauthorized data egress and alerts on anomalous large transfers.
Detects and responds to abnormal behaviors indicative of destructive malware or ransomware.
Impact at a Glance
Affected Business Functions
- Network Security Operations
- Remote Access Services
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive system information due to unauthorized access.
Recommended Actions
Key Takeaways & Next Steps
- • Fully patch all perimeter network and security appliances, especially Cisco ASA and Firepower devices.
- • Enforce Zero Trust Segmentation to contain attacker movement across workloads and network segments.
- • Deploy inline IPS and east-west traffic security to monitor and block exploits and lateral movement attempts.
- • Implement strict egress policy enforcement and continuous anomaly detection for rapid identification and blocking of data exfiltration or C2 channels.
- • Centralize multicloud visibility and security policy control to ensure real-time detection and response to policy violations and advanced threats.



