CVE-2024-20309

A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload or stop responding. This v

Severity
Medium 5.6
CVSS 3.1
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
0.001
0.9th percentile
Discovered by
Third party
Vendor-published field
Published
Mar 27, 2024
Assigned by cisco

Description

A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload or stop responding. This vulnerability is due to the incorrect handling of specific ingress traffic when flow control hardware is enabled on the AUX port. An attacker could exploit this vulnerability by reverse telnetting to the AUX port and sending specific data after connecting. A successful exploit could allow the attacker to cause the device to reset or stop responding, resulting in a denial of service (DoS) condition.

Weakness: CWE-828

Affected products

Vendor Product Category Matched by
Cisco Cisco IOS XE Software Routing & Switching cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco IOS XE Software

Vendor advisory

cisco-sa-aux-333WBz8f

Cisco IOS XE Software Auxiliary Asynchronous Port Denial of Service Vulnerability

Cisco’s rating: Medium (advisory CVSS 5.6) · Published Mar 27, 2024

Bug ID: CSCwh47363

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?