CVE-2024-20502
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-20502 is a newly disclosed vulnerability affecting the Cisco AnyConnect VPN server on Cisco Meraki MX and Z Series Teleworker Gateway devices. This issue allows unauthenticated, remote attackers to trigger a Denial of Service (DoS) condition on the affected device. The vulnerability arises due to insufficient resource management during SSL VPN session establishment. An attacker can exploit this flaw by sending a barrage of crafted HTTPS requests to the VPN server, causing it to stop accepting new connections. However, existing SSL VPN sessions remain unaffected. Upon cessation of the attack traffic, the Cisco AnyConnect VPN server recovers automatically without requiring manual intervention.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Cisco