#VU99291 Missing Release of Resource after Effective Lifetime in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2024-20481
Published: October 23, 2024
Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to resource exhaustion in the Remote Access VPN (RAVPN) service. A remote attacker can perform password spraying attack, cause resource exhaustion and perform a denial of service attack against the RAVPN service.
Note, the vulnerability is being actively exploited in the wild.