PT-2024-8248 · Cisco · Cisco Ios Xe

X.B

·

Published

2024-03-27

·

Updated

2024-04-30

·

CVE-2024-20313

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Cisco IOS XE Software (affected versions not specified)
Description: A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of OSPF updates that are processed by a device. An attacker could exploit this vulnerability by sending a malformed OSPF update to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Recommendations: Upgrade the OSPFv2 component as soon as possible to address this vulnerability. There are no workarounds that address this vulnerability.

Fix

DoS

Improper Resource Release

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-09801
CVE-2024-20313

Affected Products

Cisco Ios Xe