CVE-2024-20294Buffer Access with Incorrect Length Value in Cisco Firepower Extensible Operating System

Severity
6.6MEDIUMNVD
EPSS
0.1%
top 82.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 29

Description

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface of an affected device and having an authenticated user retrieve LLDP statistics from the

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:HExploitability: 2.1 | Impact: 4.0

Affected Packages7 packages

CVEListV5cisco/cisco_nx-os_software294 versions+293
NVDcisco/nx-os458 versions+457
NVDcisco/unified_computing_system100 versions+99
CVEListV5cisco/cisco_unified_computing_system100 versions+99

🔴Vulnerability Details

2
GHSA
GHSA-jjfr-9fr6-hh6r: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, ad2024-02-29
CVEList
CVE-2024-20294: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, ad2024-02-28

📋Vendor Advisories

1
Cisco
Cisco FXOS and NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability2024-02-28
CVE-2024-20294 — Cisco vulnerability | cvebase