#VU87896 Heap-based buffer overflow in Cisco IOS and Cisco IOS XE - CVE-2024-20307
Published: March 28, 2024
Cisco IOS
Cisco IOS XE
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the IKEv1 fragmentation code. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and cause a denial of service condition on the target system.