PT-2024-18671 · Cisco · Cisco Meraki Z Series Teleworker Gateway+2

Keane Okelley

·

Published

2024-10-02

·

Updated

2025-06-03

·

CVE-2024-20509

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices (affected versions not specified)
Description A vulnerability in the Cisco AnyConnect VPN server could allow an unauthenticated, remote attacker to hijack an AnyConnect VPN session or cause a denial of service (DoS) condition for individual users of the AnyConnect VPN service on an affected device. This issue is due to weak entropy for handlers used during the VPN authentication process and a race condition in the same process. An attacker could exploit this by correctly guessing an authentication handler and sending crafted HTTPS requests to an affected device, potentially taking over the AnyConnect VPN session from a target user or preventing the target user from establishing a session.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-20509

Affected Products

Cisco Anyconnect Vpn
Cisco Meraki Mx
Cisco Meraki Z Series Teleworker Gateway