Cisco fixed tens of vulnerabilities, including an actively exploited one
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-20329 | A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to execute operating syst A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to execute operating system commands as root. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by submitting crafted input when executing remote CLI commands over SSH. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges. An attacker with limited user privileges could use this vulnerability to gain complete control over the system. NVD description · AI analysis pending | 9.9 | 1% |
| — | ||
| CVE-2024-20412 | A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local att A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to the presence of static accounts with hard-coded passwords on an affected system. An attacker could exploit this vulnerability by logging in to the CLI of an affected device with these credentials. A successful exploit could allow the attacker to access the affected system and retrieve sensitive information, perform limited troubleshooting actions, modify some configuration options, or render the device unable to boot to the operating system, requiring a reimage of the device. NVD description · AI analysis pending | 8.4 | <1% |
| — | ||
| CVE-2024-20424 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient input validation of certain HTTP requests. An attacker could exploit this vulnerability by authenticating to the web-based management interface of an affected device and then sending a crafted HTTP request to the device. A successful exploit could allow the attacker to execute arbitrary commands with root permissions on the underlying operating system of the Cisco FMC device or to execute commands on managed Cisco Firepower Threat Defense (FTD) devices. To exploit this vulnerability, the attacker would need valid credentials for a user account with at least the role of Security Analyst (Read Only). NVD description · AI analysis pending | 9.9 | <1% |
| — | ||
| CVE-2024-20481 | Unauthenticated Remote Access VPN DoS in Cisco ASA and FTD Software CVE-2024-20481 is a denial-of-service vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software, caused by resource exhaustion (CWE-772). An unauthenticated, remote attacker can trigger it by sending a large number of VPN authentication requests to an affected device, consistent with the large-scale VPN brute-force activity Cisco Talos has documented. A successful attack exhausts device resources and causes a denial of service of the RAVPN service, potentially requiring a device reload to restore VPN service, though non-VPN functionality is unaffected. Only ASA and FTD devices with the RAVPN service enabled are affected. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-24, and trade press reports Cisco issued urgent fixes for this actively exploited bug. Do: Apply the fixed ASA/FTD Software releases specified in Cisco's advisory for CVE-2024-20481, or apply Cisco's documented mitigations (such as rate-limiting/throttling VPN authentication attempts) if patching is not immediately possible. Check RAVPN devices for bursts of failed or unusual VPN authentication requests consistent with brute-forcing, and restrict or disable internet-exposed RAVPN where it is not needed. Per CISA KEV guidance, apply vendor mitigations or discontinue use of the product if mitigations are unavailable. | 5.8 | 16% | KEV |
| masshundreds of thousands of internet-exposed Cisco ASA/FTD appliances, of which the RAVPN-enabled subset is directly vulnerable |
Full article382 words · extracted from securityaffairs.com · click to collapse

Cisco patched vulnerabilities in ASA, FMC, and FTD products, including one actively exploited in a large-scale brute-force attack campaign.
Cisco addressed multiple vulnerabilities in Adaptive Security Appliance (ASA), Secure Firewall Management Center (FMC), and Firepower Threat Defense (FTD) products, including an actively exploited flaw tracked as CVE-2024-20481.
The vulnerability CVE-2024-20481 (CVSS score of 5.8) is a Denial of Service (DoS) issue that impacts the Remote Access VPN (RAVPN) service of ASA and FTD.
An unauthenticated, remote attacker can exploit the vulnerability to cause a denial of service (DoS) of the RAVPN service.
“This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device.” reads the advisory. “Depending on the impact of the attack, a reload of the device may be required to restore the RAVPN service. Services that are not related to VPN are not affected.”
In April, Cisco Talos researchers detailed a large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials. Cisco warned customers of password-spraying attacks that have been targeting Remote Access VPN (RAVPN) services configured on Cisco Secure Firewall devices.
The company published a document containing recommendations against password spray attacks aimed at Remote Access VPN (RAVPN) services. The IT giant pointed out that the attacks are also targeting third-party VPN concentrators.
Now the company confirmed that the flaw CVE-2024-20481 is actively exploited in the wild.
“The Cisco Product Security Incident Response Team (PSIRT) is aware of malicious use of the vulnerability that is described in this advisory.” continues the advisory.
Cisco also addressed the following three critical vulnerabilities:
- CVE-2024-20412: Cisco Firepower Threat Defense Software for Firepower 1000, 2100, 3100, and 4200 Series Static Credential Vulnerability;
- CVE-2024-20424: Cisco Secure Firewall Management Center Software Command Injection Vulnerability;
- CVE-2024-20329: Cisco Adaptive Security Appliance Software SSH Remote Command Injection Vulnerability.
None of the above vulnerabilities are actively exploited in the wild.
The complete list of vulnerabilities addressed by the IT giant is available in the security advisories page.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISCO ASA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/170203/breaking-news/cisco-fixed-tens-of-vulnerabilities-including-actively-exploited-one.html