PT-2024-7457 · Cisco · Cisco Asa+1
X.B
·
Published
2024-10-23
·
Updated
2025-08-01
·
CVE-2024-20408
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Cisco Adaptive Security Appliance (ASA) Software (affected versions not specified)
Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description:
The issue is related to improper validation of data in HTTPS POST requests to the Dynamic Access Policies (DAP) feature. An attacker with valid remote access VPN user credentials could exploit this by sending a crafted HTTPS POST request, potentially causing the device to reload and resulting in a denial of service (DoS) condition.
Recommendations:
For Cisco Adaptive Security Appliance (ASA) Software, update to a version that fixes the improper validation of data in HTTPS POST requests.
For Cisco Firepower Threat Defense (FTD) Software, update to a version that fixes the improper validation of data in HTTPS POST requests.
As a temporary workaround, consider restricting access to the DAP feature until a patch is available.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asa
Cisco Ftd