CVE-2024-20513

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 639

Summary

CVE-2024-20513 is a newly discovered vulnerability affecting the Cisco AnyConnect VPN server on Cisco Meraki MX and Z Series Teleworker Gateway devices. This issue allows unauthenticated, remote attackers to cause a Denial of Service (DoS) condition for targeted users of the AnyConnect service. The vulnerability arises due to insufficient entropy in handlers used during SSL VPN session establishment. An attacker can exploit this flaw by brute-forcing valid session handlers or, in the case of an authenticated attacker, predicting them based on a valid handler. Once a valid handler is obtained, the attacker can send a crafted HTTPS request to terminate targeted SSL VPN sessions, forcing users to initiate new connections and reauthenticate.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share