Cisco IOS/IOS XE Software Vulnerability Could Lead to DoS Condition
CVE-2024-20433
7.5HIGH
Summary
A vulnerability exists in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software. This issue is caused by a buffer overflow that occurs when the software processes specially crafted RSVP packets. An unauthenticated, remote attacker could exploit this vulnerability by sending malicious RSVP traffic to an affected device, potentially causing it to reload unexpectedly. The result of such an exploit would lead to a denial of service (DoS), affecting the availability of network services.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published