CyberzSOC

Publication detail
← Back to advisories & guidance

2024-031: High Severity Vulnerabilities in Cisco Products ↗ source

March 29, 2024 CERT-EU Advisory

Summary

Six (6) high severity vulnerabilities with a CVSS score of 8.6, could allow an unauthenticated, remote attacker to cause denial of service on an packet to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition [2]. to exhaust CPU resources and stop processing traffic, resulting in a DoS condition [3]. crafted UDP packets to an affected system. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition [4]. request through an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition [5]. packet either to or through an affected device. A successful exploit could allow the attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-20259 8.6 High Cisco Cisco IOS XE Software A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to …
CVE-2024-20271 8.6 High Cisco Cisco Aironet Access Point Software A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of …
CVE-2024-20308 8.6 High Cisco IOS A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to ca…
CVE-2024-20311 8.6 High Cisco IOS A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, …
CVE-2024-20314 8.6 High Cisco Cisco IOS XE Software A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IOS XE Software could allow an unauthenticated, rem…
CVE-2024-20307 6.8 Medium Cisco IOS A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to ca…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.