PT-2024-7502 · Cisco · Cisco Asa+1

Published

2024-10-23

·

Updated

2024-11-01

·

CVE-2024-20493

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: Cisco Adaptive Security Appliance (ASA) Software (affected versions not specified) Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description: A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature could allow an unauthenticated, remote attacker to deny further VPN user authentications for several minutes, resulting in a temporary denial of service (DoS) condition. This issue is due to ineffective handling of memory resources during the authentication process. An attacker could exploit this vulnerability by sending crafted packets, which could cause resource exhaustion of the authentication process.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

BDU:2024-08890
CVE-2024-20493

Affected Products

Cisco Asa
Cisco Ftd