PT-2023-9502 · Cisco · Cisco Ios Xe+2
CVE-2024-20467
·
Publicado
2023-11-08
·
Atualizado
2024-10-03
CVSS v3.1
8.6
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE Software versions 17.12.1 through 17.12.1a
Description
The issue is related to improper management of resources during fragment reassembly in the IPv4 fragmentation reassembly code, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. An attacker could exploit this by sending specific sizes of fragmented packets to an affected device or through a Virtual Fragmentation Reassembly (VFR)-enabled interface. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. This affects Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers.
Recommendations
For Cisco IOS XE Software versions 17.12.1 through 17.12.1a, update to a newer version that addresses this issue, as Cisco has released software updates that fix the vulnerability. There are no workarounds that address this vulnerability.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Asr 1000 Series Aggregation Services Routers
Cisco Ios Xe
Cisco Cbr-8 Converged Broadband Routers