Alert - Cyber activity impacting CISCO ASA devices

Number: AL24-006
Date: April 24, 2024

Audience

This Alert is intended for IT professionals and managers of notified organizations.

Purpose

An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients.

Details

On April 24, 2024, the Canadian Centre for Cyber Security (Cyber Centre), Australian Signals Directorate's Australian Cyber Security Centre and The UK's National Cyber Security Centre (NCSC) released a joint Cyber Security AdvisoryFootnote 1 to bring awareness of newly published information by Cisco on the vulnerabilities exploited in recent incidents worldwide.

On the same day, Cisco Talos published a blog postFootnote 2 containing the latest technical details of these vulnerabilities affecting Cisco ASA devices, as well as information on two additional newly discovered vulnerabilities (CVE-2024-20353Footnote 3 and CVE-2024-20359Footnote 4) leveraged during these incidents.

Please refer to these documents for additional details and recommendations.

Report a problem on this page

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Please select all that apply:

Thank you for your help!

You will not receive a reply. For enquiries, please contact us.

Date modified: