Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2024-20260

CVE-2024-20260: 1 tracked advisory record across Cisco. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Cisco

1 advisory
  • Advisory severityHigh8.6

    High [CVE-2024-20260] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

    cisco-sa-asaftdvirtual-dos-MuenGnYRSource published Source updated

    Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms. A vulnerability in the VPN and management web servers of the Cisco Secure Firewall ASA Software and Cisco Secure FTD Software platforms could allow an unauthenticated, remote attacker to cause an affected device to run out of system memory or buffer blocks, which in turn could cause SSL VPN connection processing to slow down and eventually cease altogether. This vulnerability is due to a lack…

    Affected products in this advisory
    • Secure Firewall Adaptive Security Appliance (ASA) Software
    • Firepower 2100 Series
    • Firepower 1000 Series
    • ASA 5500-X Series Firewalls

    4 more entries in the full advisory.

    Source-reported affected versions
    • Scope: This vulnerability affects Cisco products if they are running a vulnerable release of Cisco Secure Firewall ASA Software or Secure FTD Software and have one or both of the following features configured:
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models.
    Workarounds
    • There are no workarounds that address this vulnerability.

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery