logo

CVE-2024-20353 and CVE-2024-20359: Cisco ASA and FTD Vulnerabilities Exploited by State-Sponsored Threat Actor in Espionage Campaign “ArcaneDoor”

ID: d9f87e96-40ce-5e68-ae5b-bf2063749e07

STIX ID: report--d9f87e96-40ce-5e68-ae5b-bf2063749e07

Feed Name: Arctic Wolf

Threat Score
88/100

Date Published: 2024-04-29

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

On 24 April 2024 Cisco Talos and multiple government agencies disclosed an active espionage campaign abusing Cisco ASA/FTD vulnerabilities (CVE-2024-20353 and CVE-2024-20359) to install persistent implants—Line Dancer (memory-resident shellcode loader) and Line Runner (HTTP-based Lua backdoor)—enabling root-level code execution, logging suppression, data exfiltration, and authentication bypass; the advisory urges upgrading to fixed software versions and applying hardening guidance for ASA/FTD devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.