CVE-2024-20402
A vulnerability in the SSL VPN feature for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a logic error in memory management when the device is handling SSL VPN connections. An attacker could exploit this vulnerability by sending crafted SSL/TLS packets to the SSL VPN server of the affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- EPSS probability
- 0.52%
- CWE
- CWE-788
- Published
- 2024-10-23
- Last modified
- 2026-03-13
Affected products
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
Weakness type
Related vulnerabilities
- CVE-2023-20585 — Insuffient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges...
- CVE-2026-20052 — Cisco Secure Firewall Threat Defense Software Snort 3 Memory Management Denial of Service Vulnerability
- CVE-2026-21316 — Audition | Access of Memory Location After End of Buffer (CWE-788)
- CVE-2026-25584 — iccDEV vulnerable to Stack-based Buffer Overflow in CIccTagFloatNum::GetValues()
- CVE-2025-36581 — Dell PowerEdge Platform version(s) 14G AMD BIOS v1.25.0 and prior, contain(s) an Access of Memory...
- CVE-2025-43580 — Audition | Access of Memory Location After End of Buffer (CWE-788)
- CVE-2024-20330 — Cisco Firepower Threat Defense Software for Cisco Firepower 2100 Series TCP UDP Snort 2 and Snort 2 Denial of Service Vulnerability
- CVE-2024-42425 — Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Access of Memory Location...