#VU99293 Use of insufficiently random values in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2024-20331
Published: October 24, 2024
Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient entropy in the authentication process in the session authentication functionality of the Remote Access SSL VPN feature. A remote attacker can determining the handle of an authenticating user and use it to terminate their authentication session, resulting in a denial of service condition.