Cisco IOS XE Software Vulnerability Could Lead to Unauthorized Reload and Denial of Service
CVE-2024-20313
Summary
The vulnerability presents a risk within the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software that could allow an adjacent attacker without authentication to disrupt the operation of an affected device. This issue arises from insufficient validation of OSPF updates, leading to unexpected device reloading and resulting in a denial of service (DoS). Through the exploitation of this vulnerability, an attacker could send a specially crafted OSPF update, thus provoking the affected device to restart abruptly. Organizations utilizing Cisco IOS XE Software are advised to evaluate their systems for this vulnerability and implement necessary mitigations.
Affected Version(s)
Cisco IOS XE Software 17.5.1
Cisco IOS XE Software 17.5.1a
Cisco IOS XE Software 17.6.1
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved