CVE-2024-20467

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Sep 25, 2024
Updated: Oct 3, 2024
CWE ID 399

Summary

CVE-2024-20467 is a newly discovered vulnerability affecting Cisco IOS XE Software. This issue lies in the IPv4 fragmentation reassembly code, which could be exploited by unauthenticated, remote attackers to cause a denial of service (DoS) condition on impacted devices. The vulnerability arises due to insufficient resource management during fragment reassembly. An attacker could potentially send specially crafted fragmented packets or leverage Virtual Fragmentation Reassembly (VFR) interfaces to trigger the issue. Successful exploitation may result in device reloads, leading to a DoS condition. This vulnerability affects Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers running Cisco IOS XE Software Release 17.12.1 or 17.12.1a.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share