cbcvebase.
CVE-2024-20467
published 2024-09-25

CVE-2024-20467: A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remote attacker to…

PriorityP350high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
0.98%
58.3th percentile
A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper management of resources during fragment reassembly. An attacker could exploit this vulnerability by sending specific sizes of fragmented packets to an affected device or through a Virtual Fragmentation Reassembly (VFR)-enabled interface on an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Note: This vulnerability affects Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers if they are running Cisco IOS XE Software Release 17.12.1 or 17.12.1a.

Affected

7 ranges
VendorProductVersion rangeFixed in
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscoios_xe
ciscoios_xe
ciscoios_xe
ciscoios_xe

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector targets IPv4 fragmentation reassembly — monitor for abnormal volumes of fragmented IPv4 packets directed at ASR 1000 or cBR-8 devices, particularly packets with specific/unusual fragment sizes
  • Scope is limited to Cisco IOS XE Release 17.12.1 or 17.12.1a on ASR 1000 Series and cBR-8 — use device inventory/version checks to identify exposed assets
  • VFR-enabled interfaces are an additional attack surface — audit interfaces configured with Virtual Fragmentation Reassembly (VFR) on affected platforms
  • Successful exploitation causes a device reload — alert on unexpected reloads/crashes of ASR 1000 or cBR-8 devices running affected IOS XE versions as a post-exploitation indicator
  • Track Cisco Bug ID CSCwh44152 for patch availability and additional technical details
  • ·No workarounds are available — the only remediation is upgrading to a fixed software release
  • ·Vulnerability is strictly scoped to IOS XE 17.12.1 and 17.12.1a; other IOS XE releases are not listed as affected

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.