CVE-2023-20269

Vulnerability updated 7 months ago (2024-05-04T19:49:23.557Z)
Download STIX
Preview STIX
CVE-2023-20269 is a zero-day vulnerability found in Cisco's Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. This flaw in software design or implementation has been actively exploited by ransomware groups to gain initial access to corporate networks. The exploitation of this vulnerability has been confirmed by both LockBit and the Akira ransomware gang, the latter having already claimed 125 victims since tracking began in April 2023. The Finnish National Cyber Security Centre (NCSC-FI) also issued an advisory regarding a spike in Akira ransomware incidents towards the end of 2023, which were carried out by exploiting this security flaw. The vulnerability, CVE-2023-20269, specifically impacts the VPN feature of Cisco’s ASA and FTD software. The company warned about this vulnerability being actively exploited in ransomware attacks, following which it issued an alert earlier this month. Rapid7, in its September 7 update, confirmed that "CVE-2023-20269 is being exploited in the wild" and linked it to certain behaviors they had observed and outlined in their blog post. In response to the rising threat, Cisco has urged users to apply necessary patches to mitigate the risk associated with this vulnerability. The severity of the issue is underscored by its CVSS score of 5.0, indicating a medium level of risk. As ransomware groups continue to exploit this zero-day flaw for unauthorized network access, organizations are advised to stay vigilant, monitor their network activities closely, and ensure all software is up-to-date.
Description last updated: 2024-03-21T22:11:47.510Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
Cisco
Vpn
Exploit
Vulnerability
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Akira Malware is associated with CVE-2023-20269. Akira is a potent ransomware that has been active since 2023, known for its aggressive encryption tactics and swift deployment. This malware, which brings a unique '80s aesthetic to the dark web, has quickly risen in prominence within the cybercrime landscape. It has targeted hundreds of victims gloUnspecified
6
The Lockbit Malware is associated with CVE-2023-20269. LockBit is a malicious software, or malware, known for its damaging and exploitative functions. It infiltrates systems via dubious downloads, emails, or websites, often without the user's knowledge, and can steal personal information, disrupt operations, or hold data hostage for ransom. The LockBit Unspecified
5
Source Document References
Information about the CVE-2023-20269 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securityaffairs
3 months ago
Securityaffairs
4 months ago
CERT-EU
10 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago
Securityaffairs
5 months ago
Securityaffairs
5 months ago
Securityaffairs
5 months ago
Securityaffairs
6 months ago
Securityaffairs
7 months ago
Securityaffairs
7 months ago
Securityaffairs
7 months ago
CISA
7 months ago
Securityaffairs
7 months ago
Securityaffairs
7 months ago
Securityaffairs
8 months ago
Securityaffairs
8 months ago
Securityaffairs
8 months ago