CVE-2024-20474: Integer Underflow
A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by sending a crafted IKEv2 packet to an affected system. A successful exploit could allow the attacker to cause Cisco Secure Client Software to crash, resulting in a DoS condition on the client software. Note: Cisco Secure Client Software releases 4.10 and earlier were known as Cisco AnyConnect Secure Mobility Client.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20474?
CVE-2024-20474 has been rated as critical severity due to its potential to cause a denial of service in Cisco Secure Client Software.
How do I fix CVE-2024-20474?
To fix CVE-2024-20474, upgrade Cisco Secure Client to the latest version recommended by Cisco.
What versions of Cisco software are affected by CVE-2024-20474?
CVE-2024-20474 affects specific versions of Cisco AnyConnect Secure Mobility Client and Cisco Secure Client software, including various versions listed in the advisory.
Can CVE-2024-20474 be exploited remotely?
Yes, CVE-2024-20474 can be exploited by an unauthenticated remote attacker.
What does CVE-2024-20474 allow an attacker to do?
CVE-2024-20474 allows an attacker to trigger a denial of service condition in Cisco Secure Client Software.