Cisco IOS Software and IOS XE Software Vulnerability: Heap Overflow Due to IKEv1 Fragmentation Code Flaw
CVE-2024-20307

7.5HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
27 March 2024

What is CVE-2024-20307?

A vulnerability in the IKEv1 fragmentation code of Cisco IOS and IOS XE Software enables unauthenticated remote attackers to trigger a heap overflow through specially crafted UDP packets. This condition arises when fragmented IKEv1 packets fail to reassemble correctly, allowing attackers to exploit this flaw and cause the affected device to reload. Such an exploit may lead to a denial-of-service situation. Both IPv4 and IPv6 traffic can be utilized for attacking affected systems, emphasizing the crucial need for improved security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Cisco IOS XE Software 3.4.8SG

Cisco IOS XE Software 3.10.8S

Cisco IOS XE Software 3.10.8aS

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.