CVE-2024-20312: Null Pointer Dereference
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An attacker could exploit this vulnerability by sending a crafted IS-IS packet to an affected device after forming an adjacency. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. Note: The IS-IS protocol is a routing protocol. To exploit this vulnerability, an attacker must be Layer 2-adjacent to the affected device and have formed an adjacency.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20312?
The severity of CVE-2024-20312 is categorized as a denial of service (DoS) vulnerability.
How do I fix CVE-2024-20312?
To fix CVE-2024-20312, it is recommended to apply the latest patches provided by Cisco for the affected IOS and IOS XE software.
Which devices are affected by CVE-2024-20312?
CVE-2024-20312 affects devices running Cisco IOS Software and Cisco IOS XE Software that utilize the IS-IS protocol.
What type of attack is possible with CVE-2024-20312?
CVE-2024-20312 allows an unauthenticated adjacent attacker to execute a denial of service attack on the affected device.
Is CVE-2024-20312 remotely exploitable?
No, CVE-2024-20312 requires an attacker to be adjacent to the target device to exploit this vulnerability.