Showing posts with label CVE-2024-20353. Show all posts
Showing posts with label CVE-2024-20353. Show all posts

Friday, July 5, 2024

Upgrade Cisco ASA firmware to 9.12.4.67 to fix Cisco rates CVE-2024-20358 vulnerability as MEDIUM. CVE-2024-20353 and CVE-2024-20359 vulnerabilities are rated HIGH

In 26 April 2024, Cisco recommend Cisco ASA 9.12.4.65 customer to upgrade their firmware to 9.16.4.57 to fix Cisco rates CVE-2024-20358 vulnerability as MEDIUM. CVE-2024-20353 and CVE-2024-20359 vulnerabilities are rated HIGH. It found that 9.16.x have behaviour change on LDAPS certificate checking. If the SSL certificate expired, the LDAPS will failed. 

Cisco have release 9.12.4.67 to fix those vulnerabilities for keep who want to stay at 9.12.x


Print Friendly and PDF
Share/Bookmark

Friday, April 26, 2024

Hackers backdoored Cisco ASA devices via two zero-days (CVE-2024-20353, CVE-2024-20359)

  1. Upgrade your Cisco ASA to the below versions: (Depend on your Cisco ASA support which version)
    9.16.4.57
    9.18.4.22
    9.20.2.10
  2. Check your firewall log or SIEM to see if there are any IOC IP hit your log.

For more detail of the IOC, please check:

Check your Cisco ASA compatibility:


Reference:

Print Friendly and PDF
Share/Bookmark