NULL pointer dereference in Cisco Systems, Inc products - CVE-2024-20446

 

NULL pointer dereference in Cisco Systems, Inc products - CVE-2024-20446

Published: August 29, 2024


Vulnerability identifier: #VU96606
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20446
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in the DHCPv6 relay agent. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

Cisco Nexus 3000 Series Switches
Cisco Nexus 9000 Series Switches
Cisco Nexus 9000 Series Switches NX-OS Mode
Cisco NX-OS

How to mitigate CVE-2024-20446

Install updates from vendor's website.

Cisco NX-OS - addressed in versions 8.4.1, 8.4.2, 8.4(3), 8.4(4a), 8.4(4), 8.4(5), 8.4(6a), 8.4(6), 8.4(7), 8.4(8), 8.4(9), 8.4(10), 9.3(10), 9.3(11), 9.3(12), 9.3(13), 10.2(2), 10.2(3), 10.2(3t), 10.2(3v), 10.2(4), 10.2(5), 10.2(6), 10.2(7), 10.2(8), 10.3(1), 10.3(2), 10.3(3), 10.3(4a), 10.3(5), 10.3(6), 10.4(1), 10.4(2), 10.4(3), 10.5(1)

External References

Related Security Bulletins