Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2024-20353
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C N N H 8.6 .7069 99.4 YES
AFFECTED
Product Versions Fixed
Cisco Adaptive Security Appliance (ASA) Software 9.8.1 – —
Cisco Firepower Threat Defense Software 6.2.3 – —
TIMELINE
Nov 8 Reserved by cisco
Apr 24 Added to CISA KEV, remediation due 2024-05-01
Apr 24 Published (CNA: cisco)
Aug 11 ENRICHED — CVE-2024-20353 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Received CVSS 8.6 and CPE data from NVD.
Aug 11 EXPLOIT PUBLISHED — CVE-2024-20353 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Public exploit reference added.
Description
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.
Lifecycle
Complete event history — 5 events, chronological
| Date | Event | Detail |
| November 8, 2023 | Reserved | Reserved by cisco |
| April 24, 2024 | KEV ADDED | Added to CISA KEV, remediation due 2024-05-01 |
| April 24, 2024 | Published | Published (CNA: cisco) |
| August 11, 2026 | ENRICHED | ENRICHED — CVE-2024-20353 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Received CVSS 8.6 and CPE data from NVD. |
| August 11, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2024-20353 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Public exploit reference added. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Cisco | Cisco Adaptive Security Appliance (ASA) Software | — | 9.8.1 | — |
| Cisco | Cisco Firepower Threat Defense Software | — | 6.2.3 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-20353 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.