Vulnerability Database

296,172

Total vulnerabilities in the database

CVE-2024-20435

A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root.

This vulnerability is due to insufficient validation of user-supplied input for the CLI. An attacker could exploit this vulnerability by authenticating to the system and executing a crafted command on the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root. To successfully exploit this vulnerability, an attacker would need at least guest credentials.

  • Published: Jul 17, 2024
  • Updated: Aug 9, 2025
  • CVE: CVE-2024-20435
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.8
  • AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

No CWE or OWASP classifications available.

Software From Fixed in
cisco / asyncos 11.7.0-406 11.7.0-406.x
cisco / asyncos 11.7.0-418 11.7.0-418.x
cisco / asyncos 11.7.1-006 11.7.1-006.x
cisco / asyncos 11.7.1-020 11.7.1-020.x
cisco / asyncos 11.7.1-049 11.7.1-049.x
cisco / asyncos 11.7.2-011 11.7.2-011.x
cisco / asyncos 11.8.0-414 11.8.0-414.x
cisco / asyncos 11.8.1-023 11.8.1-023.x
cisco / asyncos 11.8.3-018 11.8.3-018.x
cisco / asyncos 11.8.3-021 11.8.3-021.x
cisco / asyncos 12.0.1-268 12.0.1-268.x
cisco / asyncos 12.0.3-007 12.0.3-007.x
cisco / asyncos 12.5.1-011 12.5.1-011.x
cisco / asyncos 12.5.2-007 12.5.2-007.x
cisco / asyncos 12.5.4-005 12.5.4-005.x
cisco / asyncos 12.5.5-004 12.5.5-004.x
cisco / asyncos 12.5.6-008 12.5.6-008.x
cisco / asyncos 14.0.2-012 14.0.2-012.x
cisco / asyncos 14.0.3-014 14.0.3-014.x
cisco / asyncos 14.0.4-005 14.0.4-005.x
cisco / asyncos 14.0.5-007 14.0.5-007.x
cisco / asyncos 14.5.0-498 14.5.0-498.x
cisco / asyncos 14.5.1-016 14.5.1-016.x
cisco / asyncos 14.5.2-011 14.5.2-011.x
cisco / asyncos 15.0.0-322 15.0.0-322.x
cisco / asyncos 15.0.0-355 15.0.0-355.x
cisco / asyncos 15.1.0-287 15.1.0-287.x