NULL pointer dereference in Cisco Systems, Inc products - CVE-2024-20446
Published: August 29, 2024
Vulnerability identifier: #VU96606
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20446
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the DHCPv6 relay agent. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Affected software
Cisco Nexus 3000 Series Switches
Cisco Nexus 9000 Series Switches
Cisco Nexus 9000 Series Switches NX-OS Mode
Cisco NX-OS
Cisco Nexus 9000 Series Switches
Cisco Nexus 9000 Series Switches NX-OS Mode
Cisco NX-OS
How to mitigate CVE-2024-20446
Install updates from vendor's website.
Cisco NX-OS - addressed in versions 8.4.1, 8.4.2, 8.4(3), 8.4(4a), 8.4(4), 8.4(5), 8.4(6a), 8.4(6), 8.4(7), 8.4(8), 8.4(9), 8.4(10), 9.3(10), 9.3(11), 9.3(12), 9.3(13), 10.2(2), 10.2(3), 10.2(3t), 10.2(3v), 10.2(4), 10.2(5), 10.2(6), 10.2(7), 10.2(8), 10.3(1), 10.3(2), 10.3(3), 10.3(4a), 10.3(5), 10.3(6), 10.4(1), 10.4(2), 10.4(3), 10.5(1)