7.4

CVE-2024-20313

A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of OSPF updates that are processed by a device. An attacker could exploit this vulnerability by sending a malformed OSPF update to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Xe Version17.5.1
CiscoIos Xe Version17.5.1a
CiscoIos Xe Version17.6.1
CiscoIos Xe Version17.6.1a
CiscoIos Xe Version17.6.1w
CiscoIos Xe Version17.6.1x
CiscoIos Xe Version17.6.1y
CiscoIos Xe Version17.6.1z
CiscoIos Xe Version17.6.1z1
CiscoIos Xe Version17.6.2
CiscoIos Xe Version17.6.3
CiscoIos Xe Version17.6.3a
CiscoIos Xe Version17.6.4
CiscoIos Xe Version17.6.5
CiscoIos Xe Version17.6.5a
CiscoIos Xe Version17.7.1
CiscoIos Xe Version17.7.1a
CiscoIos Xe Version17.7.1b
CiscoIos Xe Version17.7.2
CiscoIos Xe Version17.8.1
CiscoIos Xe Version17.8.1a
CiscoIos Xe Version17.9.1
CiscoIos Xe Version17.9.1a
CiscoIos Xe Version17.9.1w
CiscoIos Xe Version17.9.1x
CiscoIos Xe Version17.9.1x1
CiscoIos Xe Version17.9.1y
CiscoIos Xe Version17.9.1y1
CiscoIos Xe Version17.9.2
CiscoIos Xe Version17.9.2a
CiscoIos Xe Version17.9.3
CiscoIos Xe Version17.9.3a
CiscoIos Xe Version17.10.1
CiscoIos Xe Version17.10.1a
CiscoIos Xe Version17.10.1b
CiscoIos Xe Version17.11.1
CiscoIos Xe Version17.11.1a
CiscoIos Xe Version17.11.99sw
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.189
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.4 2.8 4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
psirt@cisco.com 7.4 2.8 4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.