CVE-2024-20260
Last modified
CVE-2024-20260 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv), formerly Cisco Firepower Threat Defense Virtual, platforms could allow an unauthenticated, remote attacker to cause the virtual devices to run out of system memory, which could cause SSL VPN connection processing to slow down and eventually cease all together. This vulnerability is due to a lack of proper memory management for new incoming SSL/TLS connections on the virtual platforms. An attacker could exploit this vulnerability by sending a large number of new incoming SSL/TLS connections to the targeted virtual platform. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv), formerly Cisco Firepower Threat Defense Virtual, platforms could allow an unauthenticated, remote attacker to cause the virtual devices to run out of system memory, which could cause SSL VPN connection processing to slow down and eventually cease all together. This vulnerability is due to a lack of proper memory management for new incoming SSL/TLS connections on the virtual platforms. An attacker could exploit this vulnerability by sending a large number of new incoming SSL/TLS connections to the targeted virtual platform. A successful exploit could allow the attacker to deplete system memory, resulting in a denial of service (DoS) condition. The memory could be reclaimed slowly if the attack traffic is stopped, but a manual reload may be required to restore operations quickly.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-20260?
How severe is CVE-2024-20260?
How do I fix CVE-2024-20260?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-20255A vulnerability in the SOAP API of Cisco Expressway Series a…7.1
- CVE-2024-20256A vulnerability in the web-based management interface of Cis…4.8
- CVE-2024-20257A vulnerability in the web-based management interface of Cis…4.8
- CVE-2024-20258A vulnerability in the web-based management interface of Cis…6.1
- CVE-2024-20259A vulnerability in the DHCP snooping feature of Cisco IOS XE…8.6
- CVE-2024-2026The Passster plugin for WordPress is vulnerable to Stored Cr…5.4
- CVE-2024-20261A vulnerability in the file policy feature that is used to i…5.8
- CVE-2024-20262A vulnerability in the Secure Copy Protocol (SCP) and SFTP f…6.5
- CVE-2024-20263A vulnerability with the access control list (ACL) managemen…7.2
- CVE-2024-20264A vulnerability in the web-based management interface of Cis…5.4
- CVE-2024-20265A vulnerability in the boot process of Cisco Access Point (A…5.9
- CVE-2024-20266A vulnerability in the DHCP version 4 (DHCPv4) server featur…5.3
Are you affected by CVE-2024-20260?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
