CVE-2024-20481 — Cisco ASA and FTD Denial-of-Service Vulnerability
CVE-2024-20481: Cisco ASA and FTD Denial-of-Service Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Cisco |
| Product | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) |
| Date added | 2024-10-24 |
| Due date | 2024-11-14 |
| Ransomware campaign use | Unknown |
Description
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.
Required action (CISA)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-bf-dos-vDZhLqrW ; https://nvd.nist.gov/vuln/detail/CVE-2024-20481
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-20481
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog