Executive brief
A resource exhaustion vulnerability in the Remote Access VPN (RAVPN) service of Cisco ASA and FTD software allows unauthenticated remote attackers to cause a denial-of-service. Attackers can exploit this by sending a large volume of VPN authentication requests, potentially requiring a device reload to restore service.
Affected products
- Cisco Adaptive Security Appliance (ASA) Software
- Cisco Firepower Threat Defense (FTD) Software
Timeline
- 2024-10-24: disclosed
- 2024-10-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-10-24: exploited: Reported as exploited in the wild in the advisory and CISA KEV catalog.