PT-2024-7502 · Cisco · Cisco Asa+1
Published
2024-10-23
·
Updated
2024-11-01
·
CVE-2024-20493
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
Cisco Adaptive Security Appliance (ASA) Software (affected versions not specified)
Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description:
A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature could allow an unauthenticated, remote attacker to deny further VPN user authentications for several minutes, resulting in a temporary denial of service (DoS) condition. This issue is due to ineffective handling of memory resources during the authentication process. An attacker could exploit this vulnerability by sending crafted packets, which could cause resource exhaustion of the authentication process.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asa
Cisco Ftd