CVE-2024-20431
A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy. This vulnerability is due to improper assignment of geolocation data. An attacker could exploit this vulnerability by sending traffic through an affected device. A successful exploit could allow the attacker to bypass a geolocation-based access control policy and successfully send traffic to a protected device.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
- EPSS probability
- 0.40%
- CWE
- CWE-229
- Published
- 2024-10-23
- Last modified
- 2026-03-13
Affected products
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
- Cisco Cisco Firepower Threat Defense Software
Weakness type
Related vulnerabilities
- CVE-2026-59566 — Local denial-of-service
- CVE-2026-59565 — Local and kernel denial-of-service
- CVE-2025-35973 — Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare...
- CVE-2026-4736 — Math Issue in No-Chicken/Echo-Mate
- CVE-2025-31648 — Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an...
- CVE-2025-7964 — Zigbee Router Denial of Service
- CVE-2025-20268 — Cisco Secure Firewall Threat Defense Software Geolocation Remote Access VPN Bypass Vulnerability
- CVE-2024-39531 — Junos OS Evolved: ACX 7000 Series: Protocol specific DDoS configuration affects other protocols