Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Cisco issues urgent patch for ASA and FTD software vulnerabilities under active attack
Global Security

Cisco issues urgent patch for ASA and FTD software vulnerabilities under active attack

AdminBy AdminOctober 24, 2024No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


October 24, 2024Ravi LakshmananVulnerability / Network Security

Cisco said on Wednesday that it has released updates to address a widely used security flaw in the Adaptive Security Appliance (ASA) that could lead to a denial-of-service (DoS) condition.

Vulnerability, tracked as CVE-2024-20481 (CVSS score: 5.8), affects the Remote Access VPN (RAVPN) service of Cisco ASA software and Cisco Firepower Threat Defense (FTD).

A security issue caused by resource exhaustion can be exploited by unauthenticated remote attackers to cause a DoS of the RAVPN service.

“An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device,” Cisco said. said in the advisory. “A successful exploit could allow an attacker to exhaust resources, resulting in a DoS of the RAVPN service on a compromised device.”

Cyber ​​security

Restoring RAVPN service may require a device reboot depending on the effects of the attack, the networking equipment company added.

While there are no direct workarounds to address CVE-2024-20481, Cisco said customers can follow the recommendations resist password spraying attacks –

  • Enable recording
  • Configure threat detection for remote access VPN services
  • Take enforcement measures such as disabling AAA authentication and
  • Manually block connection attempts from unauthorized sources

Notably, the flaw was exploited in a malicious context by threat actors in a large-scale brute force campaign targeting VPN and SSH services.

Earlier this April, Cisco Talos marked with a flag since March 18, 2024, a surge in brute-force attacks against virtual private network (VPN) services, web application authentication interfaces, and SSH services.

These attacks exposed a wide range of hardware from various companies, including Cisco, Check Point, Fortinet, SonicWall, MikroTik, Draytek and Ubiquiti.

“Brude-force attempts use common usernames and real usernames for specific organizations,” Talos noted at the time. “All of these attacks appear to originate from TOR exit nodes and a number of other anonymous tunnels and proxies.”

Cyber ​​security

Cisco has also released patches to address three other critical vulnerabilities in the FTD software, Secure Firewall Management Center (FMC) software, and Adaptive Security Appliance (ASA) respectively –

  • CVE-2024-20412 (CVSS Score: 9.3) – A static credentials vulnerability with hardcoded passwords exists in the FTD software for the Cisco Firepower 1000, 2100, 3100, and 4200 series, which could allow an unauthenticated local attacker to gain access to a compromised system using static credentials .
  • CVE-2024-20424 (CVSS Score: 9.9) – Insufficient validation of incoming HTTP requests, a vulnerability in the FMC software management web interface that could allow an authenticated, remote attacker to execute arbitrary commands on the host operating system as the root user
  • CVE-2024-20329 (CVSS Score: 9.9) – Insufficient validation of a user input vulnerability in the ASA’s SSH subsystem could allow an authenticated, remote attacker to execute operating system commands as root

With security vulnerabilities in network devices becoming the focus of nation-state exploitation, it is critical that users apply the latest patches quickly.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.