• News/
  • https://www.theregister.com/2024/01/31/cisco_vuln_akira_attacks/

Akira ransomware attacks linked to Cisco vuln fixed in 2020

The Register
·
Connor Jones
·
Published Jan 31, 2024
·
Updated

Security researchers believe the Akira ransomware group could be exploiting a nearly four-year-old Cisco vulnerability and using it as an entry point into organizations' systems. In eight of security company TrueSec's most recent incident response engagements that involved Akira and Cisco's AnyConnect SSL VPN as the entry point, at least six of the devices were running versions vulnerable to CVE-2020-3259, which was patched in May 2020. The vulnerability lies in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) software, allowing attackers to extract secrets stored in memory in clear text such as usernames and passwords – à la CitrixBleed. TrueSec said that because there is no publicly available exploit code for the Cisco vulnerability, it means cybercriminals like those working for Akira would either need to have bought that exploit from somewhere or developed one of their own, which would require a deep understanding of the flaw. Akira is long known to be targeting Cisco VPNs as the initial access vector for ransomware attacks, but the possible exploitation of the old vulnerability is the new finding here. Analysis of past cases has been stymied by the "generally non-existent" network logs in environments, according to Heresh Zaremand, senior consultant at TrueSec, and these were barely even enough to pinpoint AnyConnect as the point of access. In one recent incident, however, the TrueSec team managed to restore s...

Read full article

Affected Software

3 affected components
Cisco AnyConnect SSL VPN=CVE-2020-3259
Cisco Adaptive Security Appliance (ASA) software
Cisco Firepower Threat Defense (FTD) software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Akira ransomware attacks linked to a Cisco vulnerability that was fixed in 2020.

2

What security implications are discussed?

The article highlights the potential exploitation of a nearly four-year-old Cisco vulnerability by ransomware attackers.

3

What products or software are affected?

The affected products include Cisco AnyConnect SSL VPN, Cisco Adaptive Security Appliance (ASA) software, and Cisco Firepower Threat Defense (FTD) software.

4

What vulnerability is associated with the Akira ransomware group?

The Akira ransomware group is believed to be exploiting Cisco vulnerability CVE-2020-3259.

5

When was the Cisco vulnerability that Akira is exploiting fixed?

The Cisco vulnerability in question was fixed in the year 2020.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203