CVE-2024-20433

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Sep 25, 2024
Updated: Oct 3, 2024
CWE ID 121
CWE ID 787

Summary

CVE-2024-20433 is a newly disclosed vulnerability affecting Cisco IOS Software and Cisco IOS XE Software. This issue arises from a buffer overflow vulnerability in the Resource Reservation Protocol (RSVP) feature, which can be exploited by unauthenticated, remote attackers. By sending crafted RSVP packets, an attacker can cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability poses a significant risk to networks utilizing the impacted Cisco software versions and should be addressed promptly by applying the available patches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share