{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/security-appliance/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cisco:nexus_dashboard_fabric_controller:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.5,"id":"CVE-2024-20444"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Adaptive Security Appliance","Secure Firewall Threat Defense"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","networking","security-appliance"],"_cs_type":"advisory","_cs_vendors":["Cisco"],"content_html":"\u003cp\u003eCisco has identified a vulnerability in the web-based management interface of the Adaptive Security Appliance (ASA) software and Secure Firewall Threat Defense (FTD) software. This flaw, tracked as CVE-2024-20444, allows an unauthenticated, remote attacker to perform a Denial of Service (DoS) attack. By sending specifically crafted HTTP requests to the targeted device, an attacker can cause the device to crash and subsequently reboot, leading to a temporary loss of network connectivity and security enforcement capabilities. This issue is significant for security operations as it targets the management plane of critical network infrastructure, potentially resulting in unauthorized service downtime. Defenders should prioritize patching affected systems to mitigate the risk of disruption to core security services.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a crash and automatic reboot of the affected Cisco ASA or FTD device. This impact leads to a total denial of network and security services provided by the appliance, effectively bypassing firewall rules and security policies for the duration of the outage. The target audience includes enterprises relying on Cisco perimeter security infrastructure for traffic control and threat mitigation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize applying software updates provided by Cisco to address CVE-2024-20444 across all internet-facing and internal management interfaces.\u003c/li\u003e\n\u003cli\u003eRestrict access to the web-based management interface of Cisco appliances to trusted management networks only, utilizing access control lists to prevent external reachability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T08:37:37Z","date_published":"2026-08-12T08:37:37Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cisco-asa-dos/","summary":"A vulnerability in the web-based management interface of Cisco ASA and Secure Firewall Threat Defense allows an unauthenticated, remote attacker to trigger a device crash via crafted HTTP requests.","title":"Denial of Service Vulnerability in Cisco ASA and FTD","url":"https://feed.craftedsignal.io/briefs/2026-08-cisco-asa-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Security-Appliance","version":"https://jsonfeed.org/version/1.1"}