Heap-based buffer overflow in Cisco Systems, Inc products - CVE-2024-20259
Published: March 28, 2024
Vulnerability identifier: #VU87886
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20259
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the DHCP snooping feature. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and cause a denial of service condition on the target system.
Affected software
Catalyst 9000 Series Switches
DNA Traffic Telemetry Appliance
Cisco IOS XE
DNA Traffic Telemetry Appliance
Cisco IOS XE
How to mitigate CVE-2024-20259
Install update from vendor's website.
Cisco IOS XE - addressed in versions Dublin-17.12.2, Cupertino-17.9.5, 17.9.5, 17.9.5a, 17.12.1x, 17.12.2, 17.12.02a, 17.12.2a, 17.12.3, 17.13.1, 17.13.1a