CVE-2024-20500
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-20500 is a vulnerability affecting the Cisco AnyConnect VPN server on Cisco Meraki MX and Z Series Teleworker Gateway devices. This issue allows unauthenticated, remote attackers to cause a Denial of Service (DoS) condition. The vulnerability stems from insufficient resource management during the establishment of TLS/SSL sessions. An attacker can exploit this flaw by sending crafted TLS/SSL messages, leading to the Cisco AnyConnect VPN server stopping acceptance of new connections. Existing SSL VPN sessions remain unaffected, and the server recovers automatically once the attack traffic ceases.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Cisco