Emergency patch: Cisco fixes bug under exploit in brute-force attacks
ID: 434d1e0b-278a-5ca5-9539-d6d60380cf7a
STIX ID: report--434d1e0b-278a-5ca5-9539-d6d60380cf7a
Feed Name: The Register (Security)
Threat Score
Cisco patched CVE-2024-20481, a medium-severity resource-exhaustion flaw in ASA and FTD RAVPN that is being actively exploited in brute-force VPN authentication campaigns. Attackers—observed using TOR exit nodes and proxies—are flooding devices with auth requests to exhaust resources or gain unauthorized access; CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog and Cisco published patches and IOCs with mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
