logo

Cisco fixes VPN DoS flaw discovered in password spray attacks

ID: b9a6ed57-2a9f-5d6e-9bd5-ee08a176f1ee

STIX ID: report--b9a6ed57-2a9f-5d6e-9bd5-ee08a176f1ee

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-10-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cisco patched CVE-2024-20481, a Remote Access VPN (RAVPN) resource-exhaustion vulnerability in ASA and Firepower Threat Defense that can allow an unauthenticated remote attacker to cause a denial of service by sending large volumes of VPN authentication requests; the flaw was identified during large-scale brute-force credential harvesting campaigns targeting multiple VPN vendors. The advisory notes the service must be enabled for exploitation, provides commands to check for SSL VPN, and also lists additional high-severity Cisco flaws with available patches or mitigations for administrators to apply.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.