PT-2024-7475 · Cisco · Cisco Asa+1

Jason Crowder

·

Published

2024-10-23

·

Updated

2025-08-15

·

CVE-2024-20495

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Cisco Adaptive Security Appliance (ASA) Software (affected versions not specified) Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description: The issue is related to insufficient input validation in the Remote Access VPN feature. This could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of client key data after the TLS session is established. An attacker could exploit this by sending a crafted key value to an affected system over the secure TLS session.
Recommendations: For Cisco Adaptive Security Appliance (ASA) Software, update to a version that fixes the improper validation of client key data. For Cisco Firepower Threat Defense (FTD) Software, update to a version that fixes the improper validation of client key data. As a temporary workaround, consider restricting access to the Remote Access VPN feature until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08855
CVE-2024-20495

Affected Products

Cisco Asa
Cisco Ftd