Cisco IOS XE Software Vulnerability Could Lead to Denial of Service
CVE-2024-20467

8.6HIGH

Key Information:

Vendor
Cisco
Status
Vendor
CVE Published:
25 September 2024

Summary

A vulnerability exists in the IPv4 fragmentation reassembly code of Cisco IOS XE Software, which may allow an unauthenticated, remote attacker to exploit this flaw and trigger a denial of service (DoS) on impacted devices. This issue stems from inadequate resource management during the process of fragment reassembly. By sending specifically sized fragmented packets or through a Virtual Fragmentation Reassembly (VFR)-enabled interface, an attacker could potentially induce a device reload, leading to service interruptions. The specific Cisco products affected include the ASR 1000 Series Aggregation Services Routers and cBR-8 Converged Broadband Routers operating on software versions 17.12.1 and 17.12.1a.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.