CVE-2024-20464

A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected

Severity
High 8.6
CVSS 3.1
Remote · no auth what this means
Exploited
Not listed
EPSS
0.006
45.1th percentile
Discovered by
Vendor
Vendor-published field
Published
Sep 25, 2024
Assigned by cisco

Description

A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of received IPv4 PIMv2 packets. An attacker could exploit this vulnerability by sending a crafted PIMv2 packet to a PIM-enabled interface on an affected device. A successful exploit could allow the attacker to cause an affected device to reload, resulting in a DoS condition. Note: This vulnerability can be exploited with either an IPv4 multicast or unicast packet.

Weakness: CWE-20

Affected products

Vendor Product Category Matched by
Cisco Cisco IOS XE Software Routing & Switching cna-assigner
Vendor-reported products (2)
  • Cisco · Cisco IOS XE Software
  • cisco · ios_xe

Vendor advisory

cisco-sa-pim-APbVfySJ

Cisco IOS XE Software Protocol Independent Multicast Denial of Service Vulnerability

Cisco’s rating: High (advisory CVSS 8.6) · Published Sep 25, 2024

Bug ID: CSCwi53919

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?