CVE-2024-20496
published 2024-09-25CVE-2024-20496: A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service…
PriorityP426medium6.1CVSS 3.1
AVAACHPRNUINSCCNINAH
EPSS
0.22%
13.3th percentile
A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system.
This vulnerability is due to incorrect handling of a specific type of malformed UDP packet. An attacker in a machine-in-the-middle position could exploit this vulnerability by sending crafted UDP packets to an affected device. A successful exploit could allow the attacker to cause the device to reboot, resulting in a DoS condition on the affected system.
Affected
159 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
| cisco | cisco_sd-wan_vedge_cloud | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3phf-8x93-jmv2: A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial o
ghsa_unreviewed·2024-09-25
CVE-2024-20496 [MEDIUM] CWE-787 GHSA-3phf-8x93-jmv2: A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial o
A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system.
This vulnerability is due to incorrect handling of a specific type of malformed UDP packet. An attacker in a machine-in-the-middle position could exploit this vulnerability by sending crafted UDP packets to an affected device. A successful exploit could allow the attacker to cause the device to reboot, resulting in a DoS condition on the affected system.
Cisco
Cisco SD-WAN vEdge Software UDP Packet Validation Denial of Service Vulnerability
vendor_cisco·2024-09-25·CVSS 6.1
CVE-2024-20496 [MEDIUM] CWE-787 Cisco SD-WAN vEdge Software UDP Packet Validation Denial of Service Vulnerability
Cisco SD-WAN vEdge Software UDP Packet Validation Denial of Service Vulnerability
A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system.
This vulnerability is due to incorrect handling of a specific type of malformed UDP packet. An attacker in a machine-in-the-middle position could exploit this vulnerability by sending crafted UDP packets to an affected device. A successful exploit could allow the attacker to cause the device to reboot, resulting in a DoS condition on the affected system.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at th
Cisco
Cisco SD-WAN vEdge Software UDP Packet Validation Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20496 Cisco SD-WAN vEdge Software UDP Packet Validation Denial of Service Vulnerability
CVE-2024-20496: Cisco SD-WAN vEdge Software UDP Packet Validation Denial of Service Vulnerability
A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to incorrect handling of a specific type of malformed UDP packet. An attacker in a machine-in-the-middle position could exploit this vulnerability by sending crafted UDP packets to an affected device. A successful exploit could allow the attacker to cause the device to reboot, resulting in a DoS condition on the affected system. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-787, CWE-787
Bug IDs: CSCwc99618, CSCwd85135
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-25
Published