Skip to content
COOEY

EXPOSURES › CVE-2024-20481

CVE-2024-20481

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-10-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-20481 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatchedransomware

Cisco ASA/FTD devices are vulnerable to remote DoS attacks via CVE-2024-20481, which is actively exploited in the wild.

Cisco's Adaptive Security Appliance and Firepower Threat Defense products contain a critical vulnerability allowing unauthenticated remote denial-of-service attacks on the RAVPN service. This poses a significant risk to DIB organizations relying on Cisco security appliances for network segmentation and traffic inspection, as attackers can disrupt critical security functions without authentication. Immediate patching and network segmentation are required to mitigate exposure.

Shame score — A critical vulnerability in a widely deployed security product that is actively exploited in the wild, though not directly leading to code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized