Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2024-20359
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L H N U H H N 6.0 .1943 97.3 YES
AFFECTED
Product Versions Fixed
Cisco Adaptive Security Appliance (ASA) Software 9.8.1 – —
Cisco Firepower Threat Defense Software 6.2.3 – —
TIMELINE
Nov 8 Reserved by cisco
Apr 24 Added to CISA KEV, remediation due 2024-05-01
Apr 24 Published (CNA: cisco)
Aug 11 ENRICHED — CVE-2024-20359 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Received CVSS 6.0 and CPE data from NVD.
Aug 11 EXPLOIT PUBLISHED — CVE-2024-20359 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Public exploit reference added.
Description
A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability.
This vulnerability is due to improper validation of a file when it is read from system flash memory. An attacker could exploit this vulnerability by copying a crafted file to the disk0: file system of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the affected device after the next reload of the device, which could alter system behavior. Because the injected code could persist across device reboots, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.
Lifecycle
Complete event history — 5 events, chronological
| Date | Event | Detail |
| November 8, 2023 | Reserved | Reserved by cisco |
| April 24, 2024 | KEV ADDED | Added to CISA KEV, remediation due 2024-05-01 |
| April 24, 2024 | Published | Published (CNA: cisco) |
| August 11, 2026 | ENRICHED | ENRICHED — CVE-2024-20359 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Received CVSS 6.0 and CPE data from NVD. |
| August 11, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2024-20359 (Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)). Public exploit reference added. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Cisco | Cisco Adaptive Security Appliance (ASA) Software | — | 9.8.1 | — |
| Cisco | Cisco Firepower Threat Defense Software | — | 6.2.3 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-20359 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Monday, October 5, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.