SB2024102440 - Denial of service in Cisco Adaptive Security Appliance and Firepower Threat Defense Software
Published: October 24, 2024
Security Bulletin ID
SB2024102440
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2024-20493)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to ineffective handling of memory resources during the authentication process within the login authentication functionality of the Remote Access SSL VPN feature. A remote attacker can cause a denial of service condition on the target system.
Remediation
Install update from vendor's website.