8.6

CVE-2024-20436

A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

 This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulnerability by sending crafted HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, causing a DoS condition on the affected device.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Xe Version3.9.0as
CiscoIos Xe Version3.9.1s
CiscoIos Xe Version3.9.2s
CiscoIos Xe Version3.10.0s
CiscoIos Xe Version3.10.1s
CiscoIos Xe Version3.10.2s
CiscoIos Xe Version3.10.2ts
CiscoIos Xe Version3.10.3s
CiscoIos Xe Version3.10.4s
CiscoIos Xe Version3.10.5s
CiscoIos Xe Version3.10.6s
CiscoIos Xe Version3.10.7s
CiscoIos Xe Version3.10.8as
CiscoIos Xe Version3.10.8s
CiscoIos Xe Version3.10.9s
CiscoIos Xe Version3.10.10s
CiscoIos Xe Version3.11.0s
CiscoIos Xe Version3.11.1s
CiscoIos Xe Version3.11.2s
CiscoIos Xe Version3.11.3s
CiscoIos Xe Version3.11.4s
CiscoIos Xe Version3.12.0s
CiscoIos Xe Version3.12.1s
CiscoIos Xe Version3.12.2s
CiscoIos Xe Version3.12.3s
CiscoIos Xe Version3.12.4s
CiscoIos Xe Version3.13.0s
CiscoIos Xe Version3.13.1s
CiscoIos Xe Version3.13.2s
CiscoIos Xe Version3.13.3s
CiscoIos Xe Version3.13.4s
CiscoIos Xe Version3.13.5s
CiscoIos Xe Version3.13.6as
CiscoIos Xe Version3.13.6s
CiscoIos Xe Version3.13.7s
CiscoIos Xe Version3.13.8s
CiscoIos Xe Version3.13.9s
CiscoIos Xe Version3.13.10s
CiscoIos Xe Version3.14.0s
CiscoIos Xe Version3.14.1s
CiscoIos Xe Version3.14.2s
CiscoIos Xe Version3.14.3s
CiscoIos Xe Version3.14.4s
CiscoIos Xe Version3.15.0s
CiscoIos Xe Version3.15.1cs
CiscoIos Xe Version3.15.1s
CiscoIos Xe Version3.15.2s
CiscoIos Xe Version3.15.3s
CiscoIos Xe Version3.15.4s
CiscoIos Xe Version3.16.0cs
CiscoIos Xe Version3.16.0s
CiscoIos Xe Version3.16.1as
CiscoIos Xe Version3.16.2s
CiscoIos Xe Version3.16.3s
CiscoIos Xe Version3.16.4as
CiscoIos Xe Version3.16.4bs
CiscoIos Xe Version3.16.4ds
CiscoIos Xe Version3.16.5s
CiscoIos Xe Version3.16.6bs
CiscoIos Xe Version3.16.6s
CiscoIos Xe Version3.16.7as
CiscoIos Xe Version3.16.7bs
CiscoIos Xe Version3.16.7s
CiscoIos Xe Version3.16.8s
CiscoIos Xe Version3.16.9s
CiscoIos Xe Version3.16.10s
CiscoIos Xe Version3.17.0s
CiscoIos Xe Version3.17.1s
CiscoIos Xe Version3.17.2s
CiscoIos Xe Version3.17.3s
CiscoIos Xe Version3.17.4s
CiscoIos Xe Version3.18.2asp
CiscoIos Xe Version16.2.1
CiscoIos Xe Version16.2.2
CiscoIos Xe Version16.3.1
CiscoIos Xe Version16.3.1a
CiscoIos Xe Version16.3.2
CiscoIos Xe Version16.3.3
CiscoIos Xe Version16.3.4
CiscoIos Xe Version16.3.5
CiscoIos Xe Version16.3.6
CiscoIos Xe Version16.3.7
CiscoIos Xe Version16.3.8
CiscoIos Xe Version16.3.9
CiscoIos Xe Version16.3.10
CiscoIos Xe Version16.3.11
CiscoIos Xe Version16.4.1
CiscoIos Xe Version16.4.2
CiscoIos Xe Version16.4.3
CiscoIos Xe Version16.5.1
CiscoIos Xe Version16.5.1b
CiscoIos Xe Version16.5.2
CiscoIos Xe Version16.5.3
CiscoIos Xe Version16.6.1
CiscoIos Xe Version16.6.2
CiscoIos Xe Version16.6.3
CiscoIos Xe Version16.6.4
CiscoIos Xe Version16.6.5
CiscoIos Xe Version16.6.6
CiscoIos Xe Version16.6.7
CiscoIos Xe Version16.6.8
CiscoIos Xe Version16.6.9
CiscoIos Xe Version16.6.10
CiscoIos Xe Version16.7.1
CiscoIos Xe Version16.7.2
CiscoIos Xe Version16.7.3
CiscoIos Xe Version16.8.1
CiscoIos Xe Version16.8.1s
CiscoIos Xe Version16.8.2
CiscoIos Xe Version16.8.3
CiscoIos Xe Version16.9.1
CiscoIos Xe Version16.9.1s
CiscoIos Xe Version16.9.2
CiscoIos Xe Version16.9.3
CiscoIos Xe Version16.9.4
CiscoIos Xe Version16.9.5
CiscoIos Xe Version16.9.6
CiscoIos Xe Version16.9.7
CiscoIos Xe Version16.9.8
CiscoIos Xe Version16.10.1
CiscoIos Xe Version16.10.1a
CiscoIos Xe Version16.10.1b
CiscoIos Xe Version16.10.1e
CiscoIos Xe Version16.10.1s
CiscoIos Xe Version16.10.2
CiscoIos Xe Version16.10.3
CiscoIos Xe Version16.11.1
CiscoIos Xe Version16.11.1a
CiscoIos Xe Version16.11.1b
CiscoIos Xe Version16.11.1s
CiscoIos Xe Version16.11.2
CiscoIos Xe Version16.12.1
CiscoIos Xe Version16.12.1a
CiscoIos Xe Version16.12.1c
CiscoIos Xe Version16.12.1s
CiscoIos Xe Version16.12.2
CiscoIos Xe Version16.12.2s
CiscoIos Xe Version16.12.3
CiscoIos Xe Version16.12.3s
CiscoIos Xe Version16.12.4
CiscoIos Xe Version16.12.4a
CiscoIos Xe Version16.12.5
CiscoIos Xe Version16.12.6
CiscoIos Xe Version16.12.7
CiscoIos Xe Version16.12.8
CiscoIos Xe Version17.1.1
CiscoIos Xe Version17.1.1s
CiscoIos Xe Version17.1.1t
CiscoIos Xe Version17.1.3
CiscoIos Xe Version17.2.1
CiscoIos Xe Version17.2.1r
CiscoIos Xe Version17.2.1v
CiscoIos Xe Version17.2.2
CiscoIos Xe Version17.2.3
CiscoIos Xe Version17.3.1
CiscoIos Xe Version17.3.1a
CiscoIos Xe Version17.3.2
CiscoIos Xe Version17.3.3
CiscoIos Xe Version17.3.4
CiscoIos Xe Version17.3.4a
CiscoIos Xe Version17.3.5
CiscoIos Xe Version17.3.6
CiscoIos Xe Version17.3.7
CiscoIos Xe Version17.3.8
CiscoIos Xe Version17.3.8a
CiscoIos Xe Version17.4.1
CiscoIos Xe Version17.4.1a
CiscoIos Xe Version17.4.1b
CiscoIos Xe Version17.4.2
CiscoIos Xe Version17.5.1
CiscoIos Xe Version17.5.1a
CiscoIos Xe Version17.6.1
CiscoIos Xe Version17.6.1a
CiscoIos Xe Version17.6.2
CiscoIos Xe Version17.6.3
CiscoIos Xe Version17.6.3a
CiscoIos Xe Version17.6.4
CiscoIos Xe Version17.6.5
CiscoIos Xe Version17.6.5a
CiscoIos Xe Version17.6.6
CiscoIos Xe Version17.6.6a
CiscoIos Xe Version17.7.1
CiscoIos Xe Version17.7.1a
CiscoIos Xe Version17.7.2
CiscoIos Xe Version17.8.1
CiscoIos Xe Version17.8.1a
CiscoIos Xe Version17.9.1
CiscoIos Xe Version17.9.1a
CiscoIos Xe Version17.9.2
CiscoIos Xe Version17.9.2a
CiscoIos Xe Version17.9.3
CiscoIos Xe Version17.9.3a
CiscoIos Xe Version17.9.4
CiscoIos Xe Version17.9.4a
CiscoIos Xe Version17.10.1
CiscoIos Xe Version17.10.1a
CiscoIos Xe Version17.10.1b
CiscoIos Xe Version17.11.1
CiscoIos Xe Version17.11.1a
CiscoIos Xe Version17.12.1
CiscoIos Xe Version17.12.1a
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.64% 0.698
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
psirt@cisco.com 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.