Cisco Adaptive Security Appliance and Firepower Threat Defense AnyConnect Access Control List Bypass Vulnerability
CVE-2024-20299
Key Information
- Vendor
- Cisco
- Status
- Cisco Adaptive Security Appliance (asa) Software
- Cisco Firepower Threat Defense Software
- Vendor
- CVE Published:
- 23 October 2024
Badges
Summary
A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have been denied to flow through an affected device. This vulnerability is due to a logic error in populating group ACLs when an AnyConnect client establishes a new session toward an affected device. An attacker could exploit this vulnerability by establishing an AnyConnect connection to the affected device. A successful exploit could allow the attacker to bypass configured ACL rules.
Affected Version(s)
Cisco Adaptive Security Appliance (ASA) Software = 9.12.3
Cisco Adaptive Security Appliance (ASA) Software = 9.8.3
Cisco Adaptive Security Appliance (ASA) Software = 9.12.1
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published