Cisco IOS Software and IOS XE Software Vulnerability: Heap Overflow Due to IKEv1 Fragmentation Code Flaw
CVE-2024-20307
What is CVE-2024-20307?
A vulnerability in the IKEv1 fragmentation code of Cisco IOS and IOS XE Software enables unauthenticated remote attackers to trigger a heap overflow through specially crafted UDP packets. This condition arises when fragmented IKEv1 packets fail to reassemble correctly, allowing attackers to exploit this flaw and cause the affected device to reload. Such an exploit may lead to a denial-of-service situation. Both IPv4 and IPv6 traffic can be utilized for attacking affected systems, emphasizing the crucial need for improved security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco IOS XE Software 3.4.8SG
Cisco IOS XE Software 3.10.8S
Cisco IOS XE Software 3.10.8aS
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved