CVE-2024-20481

Published Oct 23, 2024

Last updated 19 days ago

Overview

Description
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device. Depending on the impact of the attack, a reload of the device may be required to restore the RAVPN service. Services that are not related to VPN are not affected. Cisco Talos discussed these attacks in the blog post Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials.
Source
ykramarz@cisco.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
5.8
Impact score
1.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Severity
MEDIUM

Known exploits

Data from CISA

Vulnerability name
Cisco ASA and FTD Denial-of-Service Vulnerability
Exploit added on
Oct 24, 2024
Exploit action due
Nov 14, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-772
ykramarz@cisco.com
CWE-772

Social media

Hype score
Not currently trending
  1. Actively exploited CVE : CVE-2024-20481

    @transilienceai

    13 Nov 2024

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Actively exploited CVE : CVE-2024-20481

    @transilienceai

    10 Nov 2024

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Actively exploited CVE : CVE-2024-20481

    @transilienceai

    8 Nov 2024

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. We added ASA & FTD and Webmail vulnerabilities CVE-2024-20481 & CVE-2024-37383 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/Cge6MdMFpU & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/4sp0wbENJt

    @ScamRetrieverHQ

    8 Nov 2024

    33 Impressions

    7 Retweets

    7 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. We added ASA & FTD and Webmail vulnerabilities CVE-2024-20481 & CVE-2024-37383 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/xkvXcYkRFY & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/pKQuR3kJ2u

    @Scam_refundhq

    7 Nov 2024

    25 Impressions

    8 Retweets

    8 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Actively exploited CVE : CVE-2024-20481

    @transilienceai

    5 Nov 2024

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2024-20481 #Cisco ASA and FTD Denial-of-Service Vulnerability https://t.co/uzVnVFKZVl

    @ScyScan

    4 Nov 2024

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Actively exploited CVE : CVE-2024-20481

    @transilienceai

    4 Nov 2024

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. CVE-2024-47575 is getting exploited #inthewild. Find out more at https://t.co/cD0zNEqBsj CVE-2024-37383 is getting exploited #inthewild. Find out more at https://t.co/5zoqrMDf9r CVE-2024-20481 is getting exploited #inthewild. Find out more at https://t.co/p3faEF8Jc8

    @inthewildio

    1 Nov 2024

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Cisco ASA/FTD の脆弱性 CVE-2024-20481 が FIX:活発な悪用を確認 https://t.co/fLzXo9zBeb #Cisco #CiscoASA #CiscoFTD #DoS #Exploit

    @iototsecnews

    1 Nov 2024

    57 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨 Urgent Action Needed: Patch #Cisco ASA/FTD for Actively Exploited DoS Vulnerability (#CVE-2024-20481) https://t.co/opjdr7rhDG

    @UndercodeNews

    29 Oct 2024

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. We added ASA & FTD and Webmail vulnerabilities CVE-2024-20481 & CVE-2024-37383 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/3DEDvrRAeV & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/DwG3CgF2Tv

    @BenzEcosystemHQ

    28 Oct 2024

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. قامت شركة Cisco بإصلاح الثغرة الأمنية CVE-2024-20481، وهي ثغرة تؤثر على أجهزة ASA وFirepower والتي قد تؤدي إلى رفض الخدمة (DoS) لشبكات VPN للوصول عن بعد. تعرف على المزيد: https://t.co/HL61Pt71qq

    @CERT_Arabic

    27 Oct 2024

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. به روزرسانی اضطراری سیسکو برای پچ آسیب پذیری CVE-2024-20481 https://t.co/V43S3VqAvv

    @vulnerbyte

    27 Oct 2024

    11 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 1/6 🚨 @Cisco ASA and FTD users, patch now! 🚨 A vulnerability (CVE-2024-20481) is being actively exploited to cause denial-of-service (DoS) attacks. 💣 #cybersecurity #infosec #Cisco #ASA #FTD #vulnerability #CVE202420481 #DoS

    @Eth1calHackrZ

    26 Oct 2024

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 Urgent Alert 🚨CVE-2024-20481 poses a high risk of exploitation! Attackers can cause a denial of service on Cisco ASA and FTD using a flood of VPN authentication requests. Stay vigilant and update your defenses now! #Cybersecurity #Vulnerability #InfoSec 🔒

    @SecAideInfo

    26 Oct 2024

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. CISA Warns of Critical Vulnerabilities: CVE-2024-20481 and CVE-2024-37383 Require Immediate Attention https://t.co/WOkfOnJtCS https://t.co/IN7vKYQQPz

    @buaqbot

    26 Oct 2024

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Top 5 Trending CVEs: 1 - CVE-2024-47575 2 - CVE-2024-4947 3 - CVE-2023-26360 4 - CVE-2024-9264 5 - CVE-2024-20481 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    26 Oct 2024

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Cisco выпустила экстренный патч для бага в Adaptive Security Appliance и Firepower Threat Defense Разработчики Cisco сообщили о выпуске патча для активно использующейся уязвимости CVE-2024-20481 в Adaptive Security Appliance (ASA) и… Подробнее https://t.co/XNDu4wxxaJ https://t.

    @pc7ooo

    25 Oct 2024

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CISA Warns of Critical Vulnerabilities: CVE-2024-20481 and CVE-2024-37383 Require Immediate Attention https://t.co/ECiccrYxt8 https://t.co/dda4O0ZGij

    @evanderburg

    25 Oct 2024

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. "Cisco's Adaptive Security Appliance (ASA) users, UPDATE needed! An active flaw, CVE-2024-20481, could lead to a denial-of-service condition. Stay safe, stay updated. #Cisco #CyberSecurity" https://t.co/x4XqBLvtBb

    @SalvadorCloud

    25 Oct 2024

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 【リンク集:10月24日~25日のセキュリティ関連ニュース/記事】 <脆弱性> ・Mandiant、Fortinetの新たな脆弱性が6月から悪用されていると指摘(CVE-2024-47575) https://t.co/KkimBgKaVM ・シスコのASAとFTDにおけるVPNサービスの脆弱性が悪用される 緊急アップデートが必要(CVE-2024-20481)… https://t.co/doYH40MNvW

    @MachinaRecord

    25 Oct 2024

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. CISA Sounds Alarm on Actively Exploited Cisco and Roundcube Vulnerabilities Don't overlook the risks! Learn about actively exploited flaws in #Cisco devices & #Roundcube webmail software: CVE-2024-37383 & CVE-2024-20481 https://t.co/LbSbLgAPrg

    @the_yellow_fall

    25 Oct 2024

    79 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Cisco corrige un error que se explota en ataques de fuerza bruta ℹ️ CVE-2024-20481 ➡️ Adaptive Security Appliance (ASA) y Firepower Threat Defense (FTD) https://t.co/jCymKz76tS https://t.co/6YR8YSg9QG

    @elhackernet

    24 Oct 2024

    2954 Impressions

    7 Retweets

    38 Likes

    9 Bookmarks

    0 Replies

    1 Quote

  25. Cisco Issues Urgent Fix for ASA and FTD Software Vulnerability Under Active Attack. The vulnerability, tracked as CVE-2024-20481 (CVSS score: 5.8), affects the Remote Access VPN (RAVPN) service of Cisco ASA and Cisco Firepower Threat Defense (FTD). https://t.co/MiQSbIQgZX https:/

    @riskigy

    24 Oct 2024

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 🚨 Urgente: Cisco corrige falla crítica en sistemas de seguridad Cisco ha lanzado un parche urgente para una vulnerabilidad grave en su software ASA y FTD. Esta falla está identificada como CVE-2024-20481. Es usada en ataques reales y podría dejar fuera de servicio tu VPN de…

    @CycuraMX

    24 Oct 2024

    8836 Impressions

    51 Retweets

    111 Likes

    29 Bookmarks

    0 Replies

    2 Quotes

  27. Cisco Adaptive Security Appliance and Firepower Threat Defense Software Remote Access VPN Brute Force Denial of Service Vulnerability (CVE-2024-20481) https://t.co/SWd4Xjh95p #patchmanagement

    @eyalestrin

    24 Oct 2024

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 🛡️ We added #Cisco ASA & FTD and #Roundcube Webmail vulnerabilities CVE-2024-20481 & CVE-2024-37383 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https:

    @CISACyber

    24 Oct 2024

    4705 Impressions

    13 Retweets

    23 Likes

    3 Bookmarks

    0 Replies

    2 Quotes

  29. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2024-20481 #Cisco ASA and FTD Denial-of-Service Vulnerability https://t.co/uzVnVFKZVl

    @ScyScan

    24 Oct 2024

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 📌 أصدرت سيسكو تحديثات عاجلة لمعالجة ثغرة أمنية تم استغلالها بشكل فعّال في جهاز ASA الخاص بها، مما قد يؤدي إلى حدوث حالة انقطاع خدمة (DoS). تؤثر الثغرة، المسماة CVE-2024-20481، على خدمة VPN Remote Access في برمجيات ASA وFTD. #الامن_السيبراني https://t.co/ScckflGaCA

    @cyberetweet

    24 Oct 2024

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. Cisco has patched CVE-2024-20481, a #vulnerability affecting its ASA and Firepower devices that could lead to a denial-of-service (DoS) for Remote Access VPNs. Learn more: https://t.co/EFwAK6jmoO... https://t.co/meXZ7j1gFD

    @IT_news_for_all

    24 Oct 2024

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. Cisco has patched CVE-2024-20481, a #vulnerability affecting its ASA and Firepower devices that could lead to a denial-of-service (DoS) for Remote Access VPNs. Learn more: https://t.co/ctQgrD1j6o #cybersecurity #infosec

    @TheHackersNews

    24 Oct 2024

    10796 Impressions

    44 Retweets

    78 Likes

    9 Bookmarks

    2 Replies

    0 Quotes

  33. Active Exploits Target Cisco ASA and FTD VPNs: Urgent Update Needed (CVE-2024-20481) https://t.co/sPvCQqJ4HK

    @Dinosn

    24 Oct 2024

    4616 Impressions

    21 Retweets

    78 Likes

    23 Bookmarks

    0 Replies

    0 Quotes

  34. Active Exploits Target Cisco ASA and FTD VPNs: Urgent Update Needed Stay informed about the security issue in #Cisco ASA and FTD software (CVE-2024-20481) and its potential impact on Remote Access VPN services https://t.co/bw0QSDSZOY

    @the_yellow_fall

    24 Oct 2024

    389 Impressions

    0 Retweets

    6 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

Configurations