// For flags

CVE-2024-20494

 

Severity Score

8.6
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

A vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper data validation during the TLS 1.3 handshake. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Note: This vulnerability can also impact the integrity of a device by causing VPN HostScan communication failures or file transfer failures when Cisco ASA Software is upgraded using Cisco Adaptive Security Device Manager (ASDM).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-11-08 CVE Reserved
  • 2024-10-23 CVE Published
  • 2024-10-23 CVE Updated
  • 2024-10-24 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-1287: Improper Validation of Specified Type of Input
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.19.1
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.19.1"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.19.1.5
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.19.1.5"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.19.1.9
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.19.1.9"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.19.1.12
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.19.1.12"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.19.1.18
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.19.1.18"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.19.1.22
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.19.1.22"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.19.1.24
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.19.1.24"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.19.1.27
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.19.1.27"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.19.1.28
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.19.1.28"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.19.1.31
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.19.1.31"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.20.1
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.20.1"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.20.1.5
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.20.1.5"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.20.2
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.20.2"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.20.2.10
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.20.2.10"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.20.2.21
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.20.2.21"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.20.2.22
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.20.2.22"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Adaptive Security Appliance (ASA) Software
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software"
9.20.3
Search vendor "Cisco" for product "Cisco Adaptive Security Appliance (ASA) Software" and version "9.20.3"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Firepower Threat Defense Software
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software"
7.3.0
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software" and version "7.3.0"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Firepower Threat Defense Software
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software"
7.3.1
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software" and version "7.3.1"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Firepower Threat Defense Software
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software"
7.3.1.1
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software" and version "7.3.1.1"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Firepower Threat Defense Software
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software"
7.3.1.2
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software" and version "7.3.1.2"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Firepower Threat Defense Software
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software"
7.4.0
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software" and version "7.4.0"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Firepower Threat Defense Software
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software"
7.4.1
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software" and version "7.4.1"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Firepower Threat Defense Software
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software"
7.4.1.1
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software" and version "7.4.1.1"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Firepower Threat Defense Software
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software"
7.4.2
Search vendor "Cisco" for product "Cisco Firepower Threat Defense Software" and version "7.4.2"
en
Affected