QID 317423
Date Published: 2024-03-21
QID 317423: Cisco Internetwork Operating System (IOS) XR Software DHCP Version 4 Server Denial of Service (DoS) Vulnerability (cisco-sa-iosxr-dhcp-dos-3tgPKRdm)
IOS XR is a release train of Cisco Systems' widely deployed Internetwork Operating System (IOS).
CVE-2024-20266: A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to trigger a crash of the dhcpd process, resulting in a denial of service (DoS) condition.
Affected Products
Cisco IOS XR version prior to 7.11.1
Cisco IOS XR version 24.1 prior to 24.1.1.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XR version retrieved via Unix Auth using "show version" command.
A successful exploit could temporarily prevent network access to clients that join the network during that period and rely on the DHCPv4 server of the affected device.
Solution
Customers are advised to refer to cisco-sa-iosxr-dhcp-dos-3tgPKRdm for more information.
Vendor References
- cisco-sa-iosxr-dhcp-dos-3tgPKRdm -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dhcp-dos-3tgPKRdm
CVEs related to QID 317423
Software Advisories
| Advisory ID | Software | Component | Link |
|---|