CVE-2024-20501

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 787

Summary

CVE-2024-20501 refers to multiple denial-of-service (DoS) vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Z Series Teleworker Gateway devices. These vulnerabilities arise from insufficient validation of client-supplied parameters during SSL VPN session establishment. An unauthenticated, remote attacker can exploit these weaknesses by sending maliciously crafted HTTPS requests to an affected device's VPN server. Consequences of a successful attack include server restarts, which force users to reinitiate VPN connections and reauthenticate. Persistent assaults may prevent new SSL VPN connections from being established. Upon cessation of the attack, the Cisco AnyConnect VPN server recovers automatically.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share