Cisco IOS XR Software Vulnerability Could Lead to Denial of Service
CVE-2024-20317

7.4HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
11 September 2024

Summary

A significant vulnerability has been identified in the processing of specific Ethernet frames by Cisco IOS XR Software utilized in various Cisco Network Convergence System (NCS) platforms. This flaw allows an unauthorized adjacent attacker to send specially crafted Ethernet frames, potentially leading to the dropping of high-priority packets. As a consequence, critical control plane protocol relationships may fail, resulting in a denial of service (DoS) condition. Cisco has acknowledged the issue and released software updates to rectify this vulnerability. No workarounds are available to mitigate the risk associated with it.

Affected Version(s)

Cisco IOS XR Software 7.7.1

Cisco IOS XR Software 7.8.1

Cisco IOS XR Software 7.7.2

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.