CVE-2024-20436 - CVE House
Back to Database
Status published High CVE-2024-20436

A vulnerability in the HTTP Server feature of Cisco IOS...

Vulnerability Description

A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulnerability by sending crafted HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, causing a DoS condition on the affected device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-20436

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco IOS XE Software
Vulnerable Versions:
3.9.1S, 3.9.2S, 3.9.0aS, 3.10.0S, 3.10.1S, 3.10.2S, 3.10.3S, 3.10.4S, 3.10.5S, 3.10.6S, 3.10.2tS, 3.10.7S, 3.10.8S, 3.10.8aS, 3.10.9S, 3.10.10S, 3.11.1S, 3.11.2S, 3.11.0S, 3.11.3S, 3.11.4S, 3.12.0S, 3.12.1S, 3.12.2S, 3.12.3S, 3.12.4S, 3.13.0S, 3.13.1S, 3.13.2S, 3.13.3S, 3.13.4S, 3.13.5S, 3.13.6S, 3.13.7S, 3.13.6aS, 3.13.8S, 3.13.9S, 3.13.10S, 3.14.0S, 3.14.1S, 3.14.2S, 3.14.3S, 3.14.4S, 3.15.0S, 3.15.1S, 3.15.2S, 3.15.1cS, 3.15.3S, 3.15.4S, 3.16.0S, 3.16.1aS, 3.16.2S, 3.16.0cS, 3.16.3S, 3.16.4aS, 3.16.4bS, 3.16.5S, 3.16.4dS, 3.16.6S, 3.16.7S, 3.16.6bS, 3.16.7aS, 3.16.7bS, 3.16.8S, 3.16.9S, 3.16.10S, 3.17.0S, 3.17.1S, 3.17.2S, 3.17.3S, 3.17.4S, 16.2.1, 16.2.2, 16.3.1, 16.3.2, 16.3.3, 16.3.1a, 16.3.4, 16.3.5, 16.3.6, 16.3.7, 16.3.8, 16.3.9, 16.3.10, 16.3.11, 16.4.1, 16.4.2, 16.4.3, 16.5.1, 16.5.1b, 16.5.2, 16.5.3, 3.18.2aSP, 16.6.1, 16.6.2, 16.6.3, 16.6.4, 16.6.5, 16.6.6, 16.6.7, 16.6.8, 16.6.9, 16.6.10, 16.7.1, 16.7.2, 16.7.3, 16.8.1, 16.8.1s, 16.8.2, 16.8.3, 16.9.1, 16.9.2, 16.9.1s, 16.9.3, 16.9.4, 16.9.5, 16.9.6, 16.9.7, 16.9.8, 16.10.1, 16.10.1a, 16.10.1b, 16.10.1s, 16.10.1e, 16.10.2, 16.10.3, 16.11.1, 16.11.1a, 16.11.1b, 16.11.2, 16.11.1s, 16.12.1, 16.12.1s, 16.12.1a, 16.12.1c, 16.12.2, 16.12.3, 16.12.8, 16.12.2s, 16.12.4, 16.12.3s, 16.12.4a, 16.12.5, 16.12.6, 16.12.7, 17.1.1, 17.1.1s, 17.1.1t, 17.1.3, 17.2.1, 17.2.1r, 17.2.1v, 17.2.2, 17.2.3, 17.3.1, 17.3.2, 17.3.3, 17.3.1a, 17.3.4, 17.3.5, 17.3.4a, 17.3.6, 17.3.7, 17.3.8, 17.3.8a, 17.4.1, 17.4.2, 17.4.1a, 17.4.1b, 17.5.1, 17.5.1a, 17.6.1, 17.6.2, 17.6.1a, 17.6.3, 17.6.3a, 17.6.4, 17.6.5, 17.6.6, 17.6.6a, 17.6.5a, 17.7.1, 17.7.1a, 17.7.2, 17.10.1, 17.10.1a, 17.10.1b, 17.8.1, 17.8.1a, 17.9.1, 17.9.2, 17.9.1a, 17.9.3, 17.9.2a, 17.9.3a, 17.9.4, 17.9.4a, 17.11.1, 17.11.1a, 17.12.1, 17.12.1a

Timeline

Official Publish: September 25th, 2024
Last Modified: September 25th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Weaknesses (CWE)