Input validation error in Cisco Systems, Inc products - CVE-2024-20318

 

Input validation error in Cisco Systems, Inc products - CVE-2024-20318

Published: March 14, 2024


Vulnerability identifier: #VU87522
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20318
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the Layer 2 Ethernet services. A remote attacker on the local network can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Cisco ASR 9010 Router
Cisco ASR 9912 Router
Cisco ASR 9910 Router
Cisco ASR 9906 Router
Cisco ASR 9904 Router
Cisco ASR 9903 Router
Cisco ASR 9902 Router
Cisco ASR 9901 Router
Cisco ASR 9006 Router
Cisco ASR 9000 Series Aggregation Services Routers
Cisco IOS XRv 9000 Router
IOS XRd vRouter
Cisco ASR 9922 Router
Cisco IOS XR

How to mitigate CVE-2024-20318

Install update from vendor's website.

Cisco IOS XR - addressed in versions 7.9.2, 7.10.1

External References

Related Security Bulletins