CVE-2024-20480

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Sep 25, 2024
Updated: Oct 3, 2024
CWE ID 783
CWE ID 670

Summary

CVE-2024-20480 is a vulnerability affecting the DHCP Snooping feature of Cisco IOS XE Software on SD-Access fabric edge nodes. An unauthenticated, remote attacker can exploit this issue by sending specific IPv4 DHCP packets to an affected device, causing high CPU utilization and resulting in a denial of service (DoS) condition. The vulnerability arises from improper handling of IPv4 DHCP packets. The DoS condition necessitates a manual reload to recover.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco IOS-XE
  • Cisco IOS

Affected Vendors

  • Cisco