CVE-2024-20455

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Sep 25, 2024
Updated: Oct 24, 2024
CWE ID 371

Summary

CVE-2024-20455 is a newly identified vulnerability affecting the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller mode. This issue arises due to UTD's improper handling of specific packets that egress an SD-WAN IPsec tunnel. An unauthenticated, remote attacker can potentially exploit this vulnerability by sending crafted traffic through an SD-WAN IPsec tunnel that is configured on an affected device. Successful exploitation could trigger a denial of service (DoS) condition, causing the device to reload. Notably, SD-WAN tunnels configured with Generic Routing Encapsulation (GRE) remain unaffected by this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco IOS-XE
  • Cisco IOS XE SD-WAN
  • Cisco IOS

Affected Vendors

  • Cisco