CVE-2024-20495

HIGH

Cisco Adaptive Security Appliance Software - Unauthenticated Denial of Service via Remote Access VPN Key Validation

Title source: llm
STIX 2.1

Description

A vulnerability in the Remote Access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation of client key data after the TLS session is established. An attacker could exploit this vulnerability by sending a crafted key value to an affected system over the secure TLS session. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Scores

CVSS v3 8.6
EPSS 0.0033
EPSS Percentile 56.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (50)
cisco/adaptive_security_appliance_software 9.8.4.12
cisco/adaptive_security_appliance_software 9.8.4.15
cisco/adaptive_security_appliance_software 9.8.4.17
cisco/adaptive_security_appliance_software 9.8.4.20
cisco/adaptive_security_appliance_software 9.8.4.22
cisco/adaptive_security_appliance_software 9.8.4.25
cisco/adaptive_security_appliance_software 9.8.4.26
cisco/adaptive_security_appliance_software 9.8.4.29
cisco/adaptive_security_appliance_software 9.8.4.32
cisco/adaptive_security_appliance_software 9.8.4.33
... and 40 more
Published Oct 23, 2024
Tracked Since Feb 18, 2026