CVE-2024-20455
CVSS 3.1 Score 8.6 of 10 (high)
Details
Summary
CVE-2024-20455 is a newly identified vulnerability affecting the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller mode. This issue arises due to UTD's improper handling of specific packets that egress an SD-WAN IPsec tunnel. An unauthenticated, remote attacker can potentially exploit this vulnerability by sending crafted traffic through an SD-WAN IPsec tunnel that is configured on an affected device. Successful exploitation could trigger a denial of service (DoS) condition, causing the device to reload. Notably, SD-WAN tunnels configured with Generic Routing Encapsulation (GRE) remain unaffected by this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco IOS-XE
- Cisco IOS XE SD-WAN
- Cisco IOS
Affected Vendors
- Cisco