{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2024-20481",
  "revision": 1,
  "title": "Cisco ASA and FTD — remote access service exhausts resources",
  "summary": "The remote access service in Cisco's security appliance software (ASA, FTD) does not release resources when it should, so an unauthenticated attacker can exhaust them and take the service down.",
  "source_type": "cve",
  "severity": "medium",
  "cvss": {
    "score": 5.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L",
    "version": "3.1"
  },
  "epss": 0.1575,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2024-10-24",
    "prerequisites": "Network access to the remote access service; no credentials needed."
  },
  "remediation": {
    "patch_available": true
  },
  "kill_chain": "impact",
  "recommended_action": "Apply Cisco advisory cisco-sa-asaftd-bf-dos-vDZhLqrW now; it surfaced during a password-spraying campaign, so also review sign-in attempt volume.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-20481",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2024-20481",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-20481",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20481",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-bf-dos-vDZhLqrW"
    }
  ],
  "published_at": "2024-10-23T18:15:11.737Z",
  "issued_at": "2026-09-24T12:03:01.274Z",
  "tags": [
    "cisco",
    "asa",
    "ftd",
    "vpn",
    "denial-of-service",
    "kev"
  ]
}
