CVE-2024-20303Incomplete Cleanup in Cisco IOS XE Software

CWE-459Incomplete Cleanup4 documents4 sources
Severity
7.4HIGHNVD
EPSS
0.1%
top 81.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27

Description

A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper management of mDNS client entries. An attacker could exploit this vulnerability by connecting to the wireless network and sending a continuous stream of specific mDNS packets. A successful exploit could allow the attacker to cause the wireless c

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 2.8 | Impact: 4.0

Affected Packages2 packages

CVEListV5cisco/cisco_ios_xe_software68 versions+67
NVDcisco/ios_xe68 versions+67

🔴Vulnerability Details

2
CVEList
CVE-2024-20303: A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticate2024-03-27
GHSA
GHSA-jfv4-r4r3-xx7w: A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticate2024-03-27

📋Vendor Advisories

1
Cisco
Cisco IOS XE Software for Wireless LAN Controllers Multicast DNS Denial of Service Vulnerability2024-03-27
CVE-2024-20303 — Incomplete Cleanup in Cisco | cvebase