PT-2023-9502 · Cisco · Cisco Ios Xe+2

CVE-2024-20467

·

Publicado

2023-11-08

·

Atualizado

2024-10-03

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software versions 17.12.1 through 17.12.1a
Description The issue is related to improper management of resources during fragment reassembly in the IPv4 fragmentation reassembly code, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. An attacker could exploit this by sending specific sizes of fragmented packets to an affected device or through a Virtual Fragmentation Reassembly (VFR)-enabled interface. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. This affects Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers.
Recommendations For Cisco IOS XE Software versions 17.12.1 through 17.12.1a, update to a newer version that addresses this issue, as Cisco has released software updates that fix the vulnerability. There are no workarounds that address this vulnerability.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-07915
CVE-2024-20467

Produtos afetados

Cisco Asr 1000 Series Aggregation Services Routers
Cisco Ios Xe
Cisco Cbr-8 Converged Broadband Routers