CISA Known Exploited Vulnerability

CVE-2024-20481

Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Cisco ASA and FTD Denial-of-Service Vulnerability

Date added
BOD 22-01 due date
CWE CWE-772
Ransomware Unknown

CISA description

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.