CVE-2024-20308
HIGHCisco IOS - Unauthenticated Denial of Service via IKEv1 Fragment Reassembly
Title source: llmDescription
A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap underflow, resulting in an affected device reloading. This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerability by sending crafted UDP packets to an affected system. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. Note: Only traffic that is directed to the affected system can be used to exploit this vulnerability. This vulnerability can be triggered by IPv4 and IPv6 traffic..
References (1)
Core 1
Core References
Scores
CVSS v3
8.6
EPSS
0.0069
EPSS Percentile
72.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-787
Status
published
Products (50)
cisco/ios
12.4\(22\)md
cisco/ios
12.4\(22\)md1
cisco/ios
12.4\(22\)md2
cisco/ios
12.4\(22\)mda
cisco/ios
12.4\(22\)mda1
cisco/ios
12.4\(22\)mda2
cisco/ios
12.4\(22\)mda3
cisco/ios
12.4\(22\)mda4
cisco/ios
12.4\(22\)mda5
cisco/ios
12.4\(22\)mda6
... and 40 more
Published
Mar 27, 2024
Tracked Since
Feb 18, 2026