CVE-2024-20294 — Buffer Access with Incorrect Length Value in Cisco Firepower Extensible Operating System
Severity
6.6MEDIUMNVD
EPSS
0.1%
top 82.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 29
Description
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface of an affected device and having an authenticated user retrieve LLDP statistics from the…
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:HExploitability: 2.1 | Impact: 4.0
Affected Packages7 packages
🔴Vulnerability Details
2GHSA▶
GHSA-jjfr-9fr6-hh6r: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, ad↗2024-02-29
CVEList▶
CVE-2024-20294: A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, ad↗2024-02-28
📋Vendor Advisories
1Cisco▶
Cisco FXOS and NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability↗2024-02-28