CVE-2024-20436

A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) con

Severity
High 8.6
CVSS 3.1
Remote · no auth what this means
Exploited
Not listed
EPSS
0.009
57.1th percentile
Discovered by
Vendor
Vendor-published field
Published
Sep 25, 2024
Assigned by cisco

Description

A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulnerability by sending crafted HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, causing a DoS condition on the affected device.

Weakness: CWE-476

Affected products

Vendor Product Category Matched by
Cisco Cisco IOS XE Software Routing & Switching cna-assigner
Vendor-reported products (2)
  • Cisco · Cisco IOS XE Software
  • cisco · ios_xe

Vendor advisory

cisco-sa-httpsrvr-dos-yOZThut

Cisco IOS XE Software HTTP Server Telephony Services Denial of Service Vulnerability

Cisco’s rating: High (advisory CVSS 8.6) · Published Sep 25, 2024

Bug ID: CSCwh94964

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?