CVE-2024-20499

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 787

Summary

CVE-2024-20499 refers to multiple denial-of-service (DoS) vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Z Series Teleworker Gateway devices. These vulnerabilities, resulting from insufficient validation of client-supplied parameters during SSL VPN session establishment, can be exploited by unauthenticated, remote attackers. They may send crafted HTTPS requests to the VPN server of an affected device, leading to a server restart and disruption of SSL VPN connections. Sustained attacks could hinder the establishment of new SSL VPN connections. Upon cessation of the attack traffic, the Cisco AnyConnect VPN server recovers automatically without requiring manual intervention.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share