Cisco UTD Vulnerability Could Lead to Denial of Service (DoS) Condition
CVE-2024-20455
8.6HIGH
Summary
The vulnerability in Cisco's IOS XE Software's Unified Threat Defense (UTD) arises from the improper handling of certain network packets exiting an SD-WAN IPsec tunnel. This flaw permits unauthorized remote attackers to exploit crafted packets sent through the tunnel, leading to a potential denial of service (DoS) state. Upon successful exploitation, the affected device may reboot unexpectedly, resulting in interruptions to network services. It's important to note that SD-WAN tunnels utilizing Generic Routing Encapsulation (GRE) remain unaffected by this vulnerability.
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published