logo

New Cisco ASA and FTD features block VPN brute-force password attacks

ID: b8b4f116-ec63-5492-8b5d-d78359f444b6

STIX ID: report--b8b4f116-ec63-5492-8b5d-d78359f444b6

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-10-26

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Cisco reported large-scale brute-force and password-spray attacks against VPN services that exposed a DoS condition in ASA and FTD (CVE-2024-20481). Cisco released threat-detection features to mitigate repeated failed authentications, client-initiation attacks, and connections to internal tunnel-groups, including supported ASA/FTD versions and sample configuration commands to enable shunning of offending IPs; the report also notes operational considerations such as potential performance impact and manual removal of shunned addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.