CVE-2024-20498

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 415

Summary

CVE-2024-20498 identifies multiple vulnerabilities in the Cisco AnyConnect VPN server affecting Cisco Meraki MX and Z Series Teleworker Gateway devices, which could be exploited by unauthenticated remote attackers to induce a denial-of-service (DoS) condition. The vulnerabilities arise from inadequate validation of client-supplied parameters during SSL VPN session establishment, enabling attackers to send crafted HTTPS requests that may cause the VPN server to restart. This results in disrupted SSL VPN connections, forcing users to reauthenticate and potentially preventing new connections during an ongoing attack. To remediate this vulnerability, organizations are advised to apply security updates provided by Cisco. Given its high severity rating with a potential availability impact classified as high, organizations should address this vulnerability promptly to maintain service continuity.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share