CVE-2024-20498
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-20498 refers to multiple denial-of-service (DoS) vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Z Series Teleworker Gateway devices. These vulnerabilities result from insufficient validation of client-supplied parameters during SSL VPN session establishment. An unauthenticated, remote attacker can exploit these weaknesses by sending crafted HTTPS requests to the VPN server, causing it to restart and disrupting established SSL VPN connections. A prolonged assault may prevent new connections from forming, forcing users to reinitiate VPN sessions and reauthenticate. After the attack traffic ceases, the Cisco AnyConnect VPN server recovers automatically.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Cisco