Missing Release of Resource after Effective Lifetime in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2024-20481
Published: October 23, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to resource exhaustion in the Remote Access VPN (RAVPN) service. A remote attacker can perform password spraying attack, cause resource exhaustion and perform a denial of service attack against the RAVPN service.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2024-20481
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.4.62, 9.17.1.45, 9.18.4.29, 9.19.1.37, 9.20.2.22, 9.22.1.1