CVE-2024-20481 is a denial-of-service vulnerability affecting the Remote Access VPN (RAVPN) service in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software. An unauthenticated, remote attacker can exploit this by sending numerous VPN authentication requests, leading to resource exhaustion and a DoS of the RAVPN service, potentially requiring a device reload. This vulnerability has a CVSS score of 5.8 (MEDIUM) but a high FAUCET Risk Score of 98/100, indicating a significant threat despite the moderate CVSS. It is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered substantial community discussion and media coverage, including reports of proof-of-concept exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.2.3CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense_software:6.2.3:*:*:*:*:*:*:* | ||
6.2.3.1CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense_software:6.2.3.1:*:*:*:*:*:*:* | ||
6.2.3.2CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense_software:6.2.3.2:*:*:*:*:*:*:* | ||
6.2.3.3CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense_software:6.2.3.3:*:*:*:*:*:*:* | ||
6.2.3.4CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense_software:6.2.3.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.