CVE-2024-20299 - CVE House
Back to Database
Status published Medium CVE-2024-20299

Cisco Adaptive Security Appliance and Firepower Threat Defense AnyConnect Access Control List Bypass Vulnerability

Vulnerability Description

A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should have been denied to flow through an affected device. This vulnerability is due to a logic error in populating group ACLs when an AnyConnect client establishes a new session toward an affected device. An attacker could exploit this vulnerability by establishing an AnyConnect connection to the affected device. A successful exploit could allow the attacker to bypass configured ACL rules.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-20299

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software
Vulnerable Versions:
9.12.3, 9.8.3, 9.12.1, 9.8.1, 9.12.2, 9.8.2.45, 9.8.2, 9.8.4, 9.14.1, 9.12.4, 9.8.2.26, 9.8.2.24, 9.8.2.15, 9.8.2.14, 9.8.2.35, 9.8.2.20, 9.8.2.8, 9.8.2.17, 9.8.2.28, 9.8.2.33, 9.8.2.38, 9.8.4.25, 9.12.3.2, 9.12.3.7, 9.8.3.18, 9.8.3.14, 9.8.4.15, 9.8.4.8, 9.8.1.7, 9.8.3.29, 9.14.1.10, 9.12.2.5, 9.8.4.22, 9.12.3.12, 9.8.4.7, 9.8.4.17, 9.8.3.16, 9.8.4.20, 9.8.3.11, 9.12.1.3, 9.8.4.3, 9.12.2.4, 9.8.4.12, 9.12.1.2, 9.8.3.26, 9.8.1.5, 9.12.2.9, 9.12.3.9, 9.8.3.21, 9.8.4.10, 9.12.2.1, 9.12.4.2, 9.14.1.6, 9.8.3.8, 9.14.1.15, 9.14.1.19, 9.8.4.26, 9.12.4.4, 9.14.1.30, 9.8.4.29, 9.12.4.7, 9.15.1, 9.14.2, 9.12.4.8, 9.8.4.32, 9.12.4.10, 9.14.2.4, 9.15.1.7, 9.14.2.8, 9.12.4.13, 9.8.4.33, 9.15.1.10, 9.14.2.13, 9.8.4.34, 9.12.4.18, 9.15.1.15, 9.8.4.35, 9.14.2.15, 9.12.4.24, 9.16.1, 9.15.1.16, 9.8.4.39, 9.14.3, 9.12.4.26, 9.16.1.28, 9.14.3.1, 9.12.4.29, 9.14.3.9, 9.16.2, 9.12.4.30, 9.16.2.3, 9.8.4.40, 9.14.3.11, 9.15.1.17, 9.12.4.35, 9.8.4.41, 9.15.1.1, 9.14.3.13, 9.16.2.7, 9.12.4.37, 9.14.3.15, 9.17.1, 9.16.2.11, 9.14.3.18, 9.16.2.13, 9.12.4.39, 9.12.4.38, 9.8.4.43, 9.14.4, 9.16.2.14, 9.17.1.7, 9.12.4.40, 9.15.1.21, 9.16.3.3, 9.14.4.6, 9.16.3, 9.16.3.14, 9.17.1.9, 9.14.4.7, 9.12.4.41, 9.17.1.10, 9.8.4.44, 9.18.1, 9.12.4.47, 9.14.4.12, 9.16.3.15, 9.18.1.3, 9.17.1.11, 9.12.4.48, 9.14.4.13, 9.18.2, 9.16.3.19, 9.17.1.13, 9.12.4.50, 9.14.4.14, 9.17.1.15, 9.8.4.45, 9.12.4.52, 9.14.4.15, 9.16.3.23, 9.18.2.5, 9.16.4, 9.12.4.54, 9.14.4.17, 9.8.4.46, 9.17.1.20, 9.18.2.7, 9.19.1, 9.16.4.9, 9.12.4.55, 9.18.2.8, 9.8.4.48, 6.2.3.14, 6.4.0.1, 6.2.3.7, 6.2.3, 6.4.0.2, 6.2.3.9, 6.2.3.1, 6.2.3.2, 6.4.0.5, 6.2.3.10, 6.4.0, 6.4.0.3, 6.2.3.6, 6.4.0.4, 6.2.3.15, 6.2.3.5, 6.2.3.4, 6.2.3.3, 6.2.3.8, 6.4.0.6, 6.2.3.11, 6.2.3.12, 6.2.3.13, 6.4.0.7, 6.4.0.8, 6.6.0, 6.4.0.9, 6.2.3.16, 6.6.0.1, 6.6.1, 6.4.0.10, 6.7.0, 6.4.0.11, 6.6.3, 6.7.0.1, 6.6.4, 6.4.0.12, 6.7.0.2, 7.0.0, 6.2.3.17, 7.0.0.1, 6.6.5, 7.0.1, 7.1.0, 6.4.0.13, 6.6.5.1, 6.2.3.18, 7.0.1.1, 6.7.0.3, 6.4.0.14, 7.1.0.1, 6.6.5.2, 7.0.2, 6.4.0.15, 7.2.0, 7.0.2.1, 7.0.3, 6.6.7, 7.1.0.2, 7.2.0.1, 7.0.4, 7.2.1, 7.0.5, 6.4.0.16, 7.3.0, 7.2.2, 7.2.3, 6.6.7.1, 7.3.1, 7.1.0.3, 7.3.1.1, 6.6.7.2, 7.3.1.2

Timeline

Official Publish: October 23rd, 2024
Last Modified: October 24th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Weaknesses (CWE)