Cisco announced patches for multiple vulnerabilities in its Adaptive Security Appliance (ASA), Secure Firewall Management Center (FMC) and Firepower Threat Defense (FTD), including a flaw that was exploited.
See also: Cisco: Serious vulnerability in Firepower Management Center

Known as CVE-2024-20481 (CVSS score 5.8), the exploited issue affects the Remote Access VPN (RAVPN) service of ASA and FTD and could allow unauthenticated remote attackers to cause a denial of service (DoS) condition
Only devices running a vulnerable ASA or FTD repeater that have the RAVPN service enabled are vulnerable, the tech giant says, noting that it is aware of the vulnerability being exploited post-mortem.
Cisco says the observed attacks, which it identified in April 2024, are related to a large-scale Brute-Force campaign targeting multiple VPN and SSH services. These attacks target not only Cisco's vulnerability, but also Checkpoint ,Fortinet, SonicWall, MikroTik, Draytek, and Ubiquiti products.
See also: ArcaneDoor: Hackers use Cisco zero-day to compromise networks
Cisco published the advisory for CVE-2024-20481 as part of its semi-annual ASA, FMC, and FTD security advisory package in October 2024, which describes 50 other flaws, including three critical issues, but says it is not aware of any of them being exploited in attacks.

However, the tech giant warns that it has released PoCs for CVE-2024-20377, CVE-2024-20387, and CVE-2024-20388, three information disclosure flaws in FMC.
Cisco also released patches for 10 high-severity vulnerabilities in FTD, more than half of which also affected ASA. Another high-severity flaw was resolved in Adaptive Security Virtual Appliance (ASAv) and Secure Firewall Threat Defense Virtual (FTDv).
See also: Cisco: Brute-force attacks target VPN services
Brute-Force attacks are one of the most common methods used by cybercriminals to gain unauthorized access to systems or accounts. These attacks involve systematically trying all possible password combinations until the correct one is found. Although they can be time-consuming and require significant computing power, these techniques continue to be effective, especially on systems with weak or short passwords. More recent security practices, such as using more complex passwords and adopting two-factor authentication, help protect against such attacks.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
