CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-20329

CVSS 9.9v3.1pub. 2024-10-23upd. 2025-08-01

A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to execute operating system commands as root. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by submitting crafted input when executing remote CLI commands over SSH. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges. An attacker with limited user privileges could use this vulnerability to gain complete control over the system.

🤖 AI Analysis
How it works

The vulnerability stems from insufficient input validation in the SSH subsystem. An attacker with access to the remote CLI via SSH can send crafted input data during remote command execution. Improper processing of this data by the system results in the execution of arbitrary commands at the operating system level with root privileges (privilege escalation).

Impact

An attacker can execute arbitrary operating system commands with root privileges, which means complete takeover of the Cisco ASA device — including the ability to modify configuration, read sensitive data, and disrupt the operation of the network device.

Mitigation & patch

Apply patches available from the vendor according to the references — detailed information about patched versions is contained in the Cisco Security Advisory available at: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ssh-rce-gRAuPEUF. It is also recommended to restrict SSH access to ASA devices exclusively to trusted administrative hosts.

Who is affected

Cisco Adaptive Security Appliance (ASA) Software — specific versions indicated in the vendor references (Cisco Security Advisory cisco-sa-asa-ssh-rce-gRAuPEUF)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Cisco Adaptive Security Appliance Software

    OS
    Cisco
    9.17.19.17.1.109.17.1.119.17.1.139.17.1.159.17.1.209.17.1.309.17.1.339.17.1.79.17.1.99.18.19.18.1.39.18.29.18.2.59.18.2.7+ 12 more
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-20333CRITICAL9.9⚠ KEVPL ✓same product

RCE jako root w Cisco ASA i FTD poprzez podatny serwer VPN web

CVE-2025-20363CRITICAL9.0PL ✓same product

RCE w web services Cisco ASA, FTD, IOS, IOS XE, IOS XR przez HTTP

CVE-2020-3125CRITICAL9.8PL ✓same product

Cisco ASA — obejście uwierzytelniania Kerberos w VPN (Auth Bypass)

CVE-2020-3187CRITICAL9.1PL ✓same product

Path Traversal w Cisco ASA i FTD — nieautoryzowany dostęp do plików przez WebVPN/AnyConnect

CVE-2018-0101CRITICAL10.0PL ✓same product

Cisco ASA SSL VPN — double free umożliwiający RCE lub DoS