CVE-2024-20481
published 2024-10-23CVE-2024-20481: A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software…
PriorityP277medium5.8CVSS 3.1
AVNACLPRNUINSCCNINAL
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-11-14
Exploited in the wild
EPSS
15.95%
96.5th percentile
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service.
This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device. Depending on the impact of the attack, a reload of the device may be required to restore the RAVPN service. Services that are not related to VPN are not affected.
Cisco Talos discussed these attacks in the blog post Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials.
Affected
579 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_and_firepower_threat_defense | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Check if RAVPN/SSL VPN service is enabled on the device — exploitation is only possible when RAVPN is enabled. Run the command and look for output indicating an enabled interface. ↗
- →Look for a large volume of sequential and rapid VPN authentication requests from the same source IP as the primary attack pattern for CVE-2024-20481. ↗
- →Monitor for connection attempts to built-in/internal tunnel groups that legitimate endpoints should never connect to — this is a known attacker behaviour pattern in these brute-force campaigns. ↗
- →Detect client initiation attacks: repeated TCP/TLS session starts to the RAVPN headend that are never completed from a single host — these are used to exhaust device resources. ↗
- →A sudden drop in RAVPN service availability or device reload requirement is a post-exploitation indicator of resource exhaustion caused by this vulnerability. ↗
- ·The vulnerability can ONLY be exploited if the RAVPN service is enabled on the device. Devices without RAVPN enabled are not affected. ↗
- ·There are no workarounds available for CVE-2024-20481; patching is the only remediation. ↗
- ·New threat-detection mitigations (invalid-vpn-access, remote-access-client-initiations, remote-access-authentication) require specific minimum software versions across ASA and FTD trains before they can be enabled. ↗
- ·Enabling the new brute-force mitigation features may cause a performance impact depending on existing device configuration and traffic load. ↗
- ·Services unrelated to VPN are not affected by this vulnerability — only the RAVPN service is impacted. ↗
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
vulncheck5.8MEDIUM
cisa5.8MEDIUM
vendor_cisco5.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco ASA and FTD Denial-of-Service Vulnerability
cisa·2024-10-24·CVSS 5.8
CVE-2024-20481 [MEDIUM] CWE-772 Cisco ASA and FTD Denial-of-Service Vulnerability
Vulnerability: Cisco ASA and FTD Denial-of-Service Vulnerability
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-bf-dos-vDZhLqrW ; https://nvd.nist.gov/vuln/detail/CVE-2024-20481
Remediation Due Date: 2024-11-14
Cisco
Cisco Adaptive Security Appliance and Firepower Threat Defense Software Remote Access VPN Brute Force Denial of Service Vulnerability
vendor_cisco·2024-10-23·CVSS 5.8
CVE-2024-20481 [MEDIUM] CWE-772 Cisco Adaptive Security Appliance and Firepower Threat Defense Software Remote Access VPN Brute Force Denial of Service Vulnerability
Cisco Adaptive Security Appliance and Firepower Threat Defense Software Remote Access VPN Brute Force Denial of Service Vulnerability
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service.
This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device. Depending on the impact of the attack, a reload of the device may be required to restore the
Cisco
Cisco Adaptive Security Appliance and Firepower Threat Defense Software Remote Access VPN Brute Force Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20481 Cisco Adaptive Security Appliance and Firepower Threat Defense Software Remote Access VPN Brute Force Denial of Service Vulnerability
CVE-2024-20481: Cisco Adaptive Security Appliance and Firepower Threat Defense Software Remote Access VPN Brute Force Denial of Service Vulnerability
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device. Depending on the impact of the attack, a reload of the device may be required t
GHSA
GHSA-cp3f-3wc5-j85w: A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)
ghsa_unreviewed·2024-10-23
CVE-2024-20481 [MEDIUM] CWE-772 GHSA-cp3f-3wc5-j85w: A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service.
This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device. Depending on the impact of the attack, a reload of the device may be required to restore the RAVPN service. Services that are not related to VPN are not affected.
Cisco Talos discussed these attacks in the blog post Large-scale
VulnCheck
Cisco ASA and FTD Denial-of-Service Vulnerability
vulncheck·2024·CVSS 5.8
CVE-2024-20481 [MEDIUM] CWE-772 Cisco ASA and FTD Denial-of-Service Vulnerability
Cisco ASA and FTD Denial-of-Service Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-bf-dos-vDZhLqrW; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://eclypsium.com/blog/cisco-asa-scanning-surge-c
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Cisco warns of denial of service flaw with PoC exploit code
blogs_bleepingcomputer·2025-01-22·CVSS 5.3
CVE-2025-20128 [MEDIUM] Cisco warns of denial of service flaw with PoC exploit code
## Cisco warns of denial of service flaw with PoC exploit code
## Sergiu Gatlan
Cisco has released security updates to patch a ClamAV denial-of-service (DoS) vulnerability, which has proof-of-concept (PoC) exploit code.
Tracked as CVE-2025-20128, the vulnerability is caused by a heap-based buffer overflow weakness in the Object Linking and Embedding 2 (OLE2) decryption routine, allowing unauthenticated, remote attackers to trigger a DoS condition on vulnerable devices.
If this vulnerability is successfully exploited, it could cause the ClamAV antivirus scanning process to crash, preventing or delaying further scanning operations.
"An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device," Cisco expl
Checkpoint
28th October – Threat Intelligence Report
blogs_checkpoint·2024-10-28
CVE-2024-20481 28th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 28th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 28th October, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Grupo Aeroportuario del Centro Norte (OMA), operator of 13 airports across Mexico, was hacked by the RansomHub ransomware gang, who threatened to leak 3TB of stolen data unless a ransom is paid. The attack disrupted terminal information screens and forced OMA to activate backup systems, with no reported material adverse e
Bleepingcomputer
New Cisco ASA and FTD features block VPN brute-force password attacks
blogs_bleepingcomputer·2024-10-26·CVSS 5.8
[MEDIUM] New Cisco ASA and FTD features block VPN brute-force password attacks
## New Cisco ASA and FTD features block VPN brute-force password attacks
## Lawrence Abrams
Cisco has added new security features that significantly mitigate brute-force and password spray attacks on Cisco ASA and Firepower Threat Defense (FTD), helping protect the network from breaches and reducing resource utilization on devices.
Password spray and brute force attacks are similar in that they both attempt to gain unauthorized access to an online account by guessing a password.
However, password spray attacks will attempt to simultaneously use the same passwords across multiple accounts to evade defenses. In contrast, brute force attacks repeatedly target a single account with different password attempts.
In April, Cisco disclosed that threat actors were conducting massive brute-forc
Bleepingcomputer
Cisco fixes VPN DoS flaw discovered in password spray attacks
blogs_bleepingcomputer·2024-10-24·CVSS 5.8
CVE-2024-20481 [MEDIUM] Cisco fixes VPN DoS flaw discovered in password spray attacks
## Cisco fixes VPN DoS flaw discovered in password spray attacks
## Bill Toulas
Cisco fixed a denial of service flaw in its Cisco ASA and Firepower Threat Defense (FTD) software, which was discovered during large-scale brute force attacks against Cisco VPN devices in April.
The flaw is tracked as CVE-2024-20481 and impacts all versions of Cisco ASA and Cisco FTD up until the latest versions of the software.
"A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service," reads the CVE-2024-20481 security advisory .
"This vulnerability is due to resource exhaustion. An attacker could expl
2024-10-23
Published
2024-10-24
Added to CISA KEV
Exploited in the wild