CVE-2024-20481 — Cisco Adaptive Security Appliance (ASA) Software
CISA KEVRansomwareAs of 2025-10-21, CVE-2024-20481 is a MEDIUM-severity vulnerability in Cisco Adaptive Security Appliance (ASA) Software, CVSS v3.1 5.8, EPSS 11.1% (93.5th percentile). It is listed in the CISA Known Exploited Vulnerabilities catalog (added 2024-10-24), with a US federal remediation deadline of 2024-11-14, and CISA links it to known ransomware campaigns. Threadlinqs Intelligence links 1 tracked threat campaign to CVE-2024-20481, most recently “Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow Copy Deletion (SANS ISC Forensic Reconstruction, May 2026)”.
Last updated: 2025-10-21
What is CVE-2024-20481?
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device. Depending on the impact of the attack, a reload of the device may be required to restore the RAVPN service. Services that are not related to VPN are not affected. Cisco Talos discussed these attacks in the blog post Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials.
The record classifies CVE-2024-20481 under weakness class CWE-772. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs no user interaction. 2 affected-product entries are recorded, across 1 vendor, listed below. The identifier was first published 690 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 5.8 — MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L - EPSS (FIRST)
- 11.1% probability of exploitation in the next 30 days, higher than 93.5% of all scored CVEs
- CISA KEV
- Listed since 2024-10-24, federal remediation deadline 2024-11-14 — used in known ransomware campaigns
- Threadlinqs priority
- 10/10 — CISA lists it as used in ransomware, which Threadlinqs scores at the maximum
- Published
- 2024-10-23, last modified 2025-10-21
Is CVE-2024-20481 being exploited?
CISA added CVE-2024-20481 to the Known Exploited Vulnerabilities catalog on 2024-10-24, which means the agency holds evidence of exploitation in the wild; US federal civilian agencies had to remediate it by 2024-11-14 under BOD 22-01. CISA flags the vulnerability as one used in known ransomware campaigns. It currently carries a trending score of 38 in the Threadlinqs vulnerability feed.
Affected products and versions
- Cisco: Adaptive Security Appliance (ASA) Software, Firepower Threat Defense Software
How to fix CVE-2024-20481
Because CVE-2024-20481 is KEV-listed, US federal civilian agencies were required to apply the vendor fix, or stop using the product, by 2024-11-14. No vendor patch reference has been recorded for CVE-2024-20481 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.
Threat activity tracking CVE-2024-20481
1 tracked threat in the Threadlinqs corpus references CVE-2024-20481, either in the campaign’s CVE list or as an indicator on the campaign record.
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow Copy Deletion (SANS ISC Forensic Reconstruction, May 2026) — HIGH · 2026-05-27
Sources
Seeded from cveorg and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.
← all vulnerabilities · Markdown version · Threadlinqs Intelligence