EXPOSURES › CVE-2024-20481
CVE-2024-20481
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco ASA/FTD devices are vulnerable to remote DoS attacks via CVE-2024-20481, which is actively exploited in the wild.
Cisco's Adaptive Security Appliance and Firepower Threat Defense products contain a critical vulnerability allowing unauthenticated remote denial-of-service attacks on the RAVPN service. This poses a significant risk to DIB organizations relying on Cisco security appliances for network segmentation and traffic inspection, as attackers can disrupt critical security functions without authentication. Immediate patching and network segmentation are required to mitigate exposure.
Shame score — A critical vulnerability in a widely deployed security product that is actively exploited in the wild, though not directly leading to code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |