CVE-2024-20464

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Sep 25, 2024
Updated: Oct 24, 2024
CWE ID 20

Summary

CVE-2024-20464 is a newly disclosed vulnerability affecting the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software. This issue allows unauthenticated, remote attackers to trigger a denial of service (DoS) condition on affected devices. The vulnerability stems from insufficient validation of IPv4 PIMv2 packets, enabling an attacker to send a crafted packet to a PIM-enabled interface. Successful exploitation could result in the affected device reloading, leading to a DoS condition. Notably, this vulnerability can be exploited using both IPv4 multicast and unicast packets.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share