Cisco IOS XE Software Vulnerability Could Lead to Unauthorized Reload and Denial of Service
CVE-2024-20313

7.4HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
24 April 2024

Badges

👾 Exploit Exists

Summary

The vulnerability presents a risk within the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software that could allow an adjacent attacker without authentication to disrupt the operation of an affected device. This issue arises from insufficient validation of OSPF updates, leading to unexpected device reloading and resulting in a denial of service (DoS). Through the exploitation of this vulnerability, an attacker could send a specially crafted OSPF update, thus provoking the affected device to restart abruptly. Organizations utilizing Cisco IOS XE Software are advised to evaluate their systems for this vulnerability and implement necessary mitigations.

Affected Version(s)

Cisco IOS XE Software 17.5.1

Cisco IOS XE Software 17.5.1a

Cisco IOS XE Software 17.6.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.