CVE-2024-20513
Oct. 8, 2024, 9:16 p.m.
Tags
CVSS Score
Products Impacted
Vendor | Product | Versions |
---|---|---|
cisco |
|
|
Description
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition for targeted users of the AnyConnect service on an affected device. This vulnerability is due to insufficient entropy for handlers that are used during SSL VPN session establishment. An unauthenticated attacker could exploit this vulnerability by brute forcing valid session handlers. An authenticated attacker could exploit this vulnerability by connecting to the AnyConnect VPN service of an affected device to retrieve a valid session handler and, based on that handler, predict further valid session handlers. The attacker would then send a crafted HTTPS request using the brute-forced or predicted session handler to the AnyConnect VPN server of the device. A successful exploit could allow the attacker to terminate targeted SSL VPN sessions, forcing remote users to initiate new VPN connections and reauthenticate.
Weaknesses
CWE-639
Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CWE ID: 639Date
Published: Oct. 2, 2024, 7:15 p.m.
Last Modified: Oct. 8, 2024, 9:16 p.m.
Status : Analyzed
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
ykramarz@cisco.com
CPEs
Type | Vendor | Product | Version | Update | Edition | Language | Software Edition | Target Software | Target Hardware | Other Information |
---|---|---|---|---|---|---|---|---|---|---|
o | cisco | meraki_mx65_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx65 | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx64_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx64 | - | / | / | / | / | / | / | / |
o | cisco | meraki_z4c_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_z4c | - | / | / | / | / | / | / | / |
o | cisco | meraki_z4_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_z4 | - | / | / | / | / | / | / | / |
o | cisco | meraki_z3c_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_z3c | - | / | / | / | / | / | / | / |
o | cisco | meraki_z3_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_z3 | - | / | / | / | / | / | / | / |
o | cisco | meraki_vmx_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_vmx | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx600_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx600 | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx450_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx450 | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx400_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx400 | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx250_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx250 | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx105_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx105 | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx100_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx100 | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx95_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx95 | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx85_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx85 | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx84_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx84 | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx75_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx75 | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx68w_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx68w | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx68cw_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx68cw | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx68_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx68 | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx67w_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx67w | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx67c_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx67c | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx67_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx67 | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx65w_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx65w | - | / | / | / | / | / | / | / |
o | cisco | meraki_mx64w_firmware | / | / | / | / | / | / | / | / |
h | cisco | meraki_mx64w | - | / | / | / | / | / | / | / |
CVSS Data
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Base Score
Exploitability Score
Impact Score
Base Severity
MEDIUMCVSS Vector String
The CVSS vector string provides an in-depth view of the vulnerability metrics.
View Vector StringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L