Cisco IOS and IOS XE Software Vulnerability Could Lead to Device Reload and Denial of Service
CVE-2024-20311
7.5HIGH
What is CVE-2024-20311?
The vulnerability arises from the improper handling of Locator ID Separation Protocol (LISP) packets within Cisco IOS Software and Cisco IOS XE Software. An unauthenticated remote attacker can exploit this flaw by sending specially crafted LISP packets to targeted devices. This could result in the affected device experiencing a reload, effectively leading to a denial of service condition. The exploitation can occur over both IPv4 and IPv6 transport mechanisms, amplifying the potential impact on affected networks.
Affected Version(s)
Cisco IOS XE Software 3.7.0S
Cisco IOS XE Software 3.7.1S
Cisco IOS XE Software 3.7.2S