logo

CVE-2024-20353 and CVE-2024-20359

ID: 65aeb474-abd8-50c0-abc7-f03e05b5178a

STIX ID: report--65aeb474-abd8-50c0-abc7-f03e05b5178a

Feed Name: Arctic Wolf Blog

Threat Score
80/100

Date Published: 2024-04-29

Date Updated: 2026-04-27

...
...

Cisco Talos and government agencies disclosed an active espionage campaign targeting Cisco ASA/FTD devices that abused CVE-2024-20353 (DoS) and CVE-2024-20359 (persistent local code execution) to establish persistence; adversaries deployed Line Dancer (memory-resident shellcode loader) and Line Runner (persistent Lua HTTP backdoor) to exfiltrate data, disable logging, execute commands, and create persistent remote access. Cisco and partners recommend upgrading to fixed software versions and applying device hardening and access controls to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.