PT-2023-9502 · Cisco · Cisco Ios Xe+2
Published
2023-11-08
·
Updated
2024-10-03
·
CVE-2024-20467
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE Software versions 17.12.1 through 17.12.1a
Description
The issue is related to improper management of resources during fragment reassembly in the IPv4 fragmentation reassembly code, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. An attacker could exploit this by sending specific sizes of fragmented packets to an affected device or through a Virtual Fragmentation Reassembly (VFR)-enabled interface. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. This affects Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers.
Recommendations
For Cisco IOS XE Software versions 17.12.1 through 17.12.1a, update to a newer version that addresses this issue, as Cisco has released software updates that fix the vulnerability. There are no workarounds that address this vulnerability.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asr 1000 Series Aggregation Services Routers
Cisco Ios Xe
Cisco Cbr-8 Converged Broadband Routers