← Vulnerability feed

Vulnerability record · CVE-2024-20481 · published 23 October 2024

CVE-2024-20481: Cisco ASA and FTD RAVPN resource exhaustion denial of service

Cisco · Secure Firewall Threat Defense

Cisco ASA and FTD Remote Access VPN services can be driven into resource exhaustion by a flood of VPN authentication requests. The flaw is a resource leak (CWE-772) in the RAVPN service, and recovery may require reloading the device. It matters because it lets an unauthenticated remote attacker take down VPN access for an organization without any credentials.

5.8 CVSS 3.1 Medium CISA KEV since 24 Oct 2024 EPSS 16% · top 3.2% CWE-772 · CWE-772
5.8CVSS 3.1 base score
16%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
2References
11 Aug 2026Last modified by NVD

Description

A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device. Depending on the impact of the attack, a reload of the device may be required to restore the RAVPN service. Services that are not related to VPN are not affected. Cisco Talos discussed these attacks in the blog post Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with known exploitation and a high EPSS percentile, but the direct impact is a limited availability loss to the VPN service rather than code execution or data compromise.

What it is

Cisco ASA and FTD Remote Access VPN services can be driven into resource exhaustion by a flood of VPN authentication requests. The flaw is a resource leak (CWE-772) in the RAVPN service, and recovery may require reloading the device. It matters because it lets an unauthenticated remote attacker take down VPN access for an organization without any credentials.

Impact

An attacker can exhaust resources and cause a denial of service of the RAVPN service, disrupting remote access VPN connectivity. Depending on the attack's impact, a device reload may be needed to restore service; non-VPN services are unaffected.

Attack surface

Reachable over the network through the RAVPN service with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The attack is delivered by sending a large volume of VPN authentication requests to the affected device.

Exploitation

CVE-2024-20481 is listed in CISA KEV (added 2024-10-24), indicating known exploitation, and EPSS shows a 30-day probability of 0.1575 (96.7th percentile). Cisco Talos ties the activity to large-scale brute-force campaigns against VPN and SSH services using common credentials.

What to do

  • Apply the Cisco vendor advisory fixes for ASA and FTD RAVPN as the first action.
  • If patching cannot be done immediately, follow Cisco's documented mitigations or discontinue use of the affected product per CISA's required action.
  • Restrict or rate-limit exposure of RAVPN authentication endpoints to trusted networks where feasible.
  • Monitor and throttle repeated failed VPN authentication attempts to blunt brute-force and resource-exhaustion traffic.
  • Track CISA KEV remediation due date (2024-11-14) and confirm completion.

Detection

  • Alert on spikes in VPN authentication request volume or failed login rates against ASA/FTD RAVPN endpoints.
  • Monitor device resource metrics (CPU, memory, session counts) for exhaustion correlated with authentication floods.
  • Review logs for large-scale brute-force patterns using common login credentials, as described by Cisco Talos.
  • Watch for unexpected RAVPN service restarts or device reloads following authentication bursts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-20481 to the Known Exploited Vulnerabilities catalog on 24 October 2024 as "Cisco ASA and FTD Denial-of-Service Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 14 November 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-20481 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2024-20481), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.