Junglewise Threat Intelligence

CVE-2024-20481: Cisco ASA and FTD Denial-of-Service Vulnerability

CVE-2024-20481 · Severity: critical · CVSS 5.8 · Exploited in the wild · Published 2024-10-24

Technologies: Cisco Adaptive Security Appliance (ASA) Software, Cisco Adaptive Security Appliance (ASA), Cisco Firepower Threat Defense (FTD). Vendors: Cisco.

Executive brief

A resource exhaustion vulnerability in the Remote Access VPN (RAVPN) service of Cisco ASA and FTD software allows unauthenticated remote attackers to cause a denial-of-service. Attackers can exploit this by sending a large volume of VPN authentication requests, potentially requiring a device reload to restore service.

Affected products

  • Cisco Adaptive Security Appliance (ASA) Software
  • Cisco Firepower Threat Defense (FTD) Software

Timeline

  • 2024-10-24: disclosed
  • 2024-10-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-10-24: exploited: Reported as exploited in the wild in the advisory and CISA KEV catalog.

Related threats