PT-2023-9502 · Cisco · Cisco Ios Xe+2

Published

2023-11-08

·

Updated

2024-10-03

·

CVE-2024-20467

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software versions 17.12.1 through 17.12.1a
Description The issue is related to improper management of resources during fragment reassembly in the IPv4 fragmentation reassembly code, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. An attacker could exploit this by sending specific sizes of fragmented packets to an affected device or through a Virtual Fragmentation Reassembly (VFR)-enabled interface. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. This affects Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers.
Recommendations For Cisco IOS XE Software versions 17.12.1 through 17.12.1a, update to a newer version that addresses this issue, as Cisco has released software updates that fix the vulnerability. There are no workarounds that address this vulnerability.

Fix

DoS

Weakness Enumeration

Related Identifiers

BDU:2024-07915
CVE-2024-20467

Affected Products

Cisco Asr 1000 Series Aggregation Services Routers
Cisco Ios Xe
Cisco Cbr-8 Converged Broadband Routers