CVE-2024-20304
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2024
Last modified:
03/10/2024
Description
A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust the UDP packet memory of an affected device.<br />
<br />
This vulnerability exists because the Mtrace2 code does not properly handle packet memory. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to exhaust the incoming UDP packet memory. The affected device would not be able to process higher-level UDP-based protocols packets, possibly causing a denial of service (DoS) condition.<br />
Note: This vulnerability can be exploited using IPv4 or IPv6.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:cisco:ios_xr:7.7.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:7.7.2:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:7.7.21:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:7.8.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:7.8.2:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:7.8.12:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:7.8.22:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:7.9.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:7.9.2:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:7.9.21:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:7.10.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:7.10.2:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:7.11.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:7.11.2:*:*:*:*:*:*:* | ||
cpe:2.3:o:cisco:ios_xr:24.1.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page