Integer overflow in Cisco Systems, Inc products - CVE-2024-20434

 

Integer overflow in Cisco Systems, Inc products - CVE-2024-20434

Published: September 26, 2024


Vulnerability identifier: #VU97722
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20434
CWE-ID: CWE-190
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper handling of frames with VLAN tag information. A remote attacker on the local network can pass specially crafted data to the application, trigger integer overflow and cause a denial of service condition on the target system.


Affected software

Catalyst 9300X Series Switches
Catalyst 9400X Supervisor Engines
Catalyst 9500X Series Switches
Catalyst 9600 Series Switches
Cisco IOS XE

How to mitigate CVE-2024-20434

Install update from vendor's website.

Cisco IOS XE - addressed in versions Dublin-17.12.4, 17.6.8, 17.9.6, 17.12.4, 17.15.1, 17.15.1a, 17.15.1b

External References

Related Security Bulletins