Cisco IOS XE Software Vulnerability Could Lead to Denial of Service Condition
CVE-2024-20480

8.6HIGH

Key Information:

Vendor
Cisco
Status
Vendor
CVE Published:
25 September 2024

Summary

A vulnerability exists in the DHCP Snooping feature of Cisco IOS XE Software, specifically on Software-Defined Access (SD-Access) fabric edge nodes. This flaw enables an unauthenticated, remote attacker to send specially crafted IPv4 DHCP packets to affected devices, leading to significant CPU resource exhaustion. As a result, the device may enter a denial of service state, thereby ceasing all network processing and requiring a manual restart for recovery. Proper security measures must be taken to mitigate the risk associated with this vulnerability.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.