CVE-2024-20496 - CVE House
Back to Database
Status published Medium CVE-2024-20496

Cisco SD-WAN vEdge Routers Denial of Service Vulnerability

Vulnerability Description

A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to incorrect handling of a specific type of malformed UDP packet. An attacker in a machine-in-the-middle position could exploit this vulnerability by sending crafted UDP packets to an affected device. A successful exploit could allow the attacker to cause the device to reboot, resulting in a DoS condition on the affected system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-20496

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco SD-WAN vEdge Cloud, Cisco SD-WAN vEdge router
Vulnerable Versions:
19.2.1, 20.1.12, 18.4.4, 19.3.0, 18.3.8, 19.2.2, 20.1.1, 18.3.6, 18.4.3, 18.4.302, 18.4.5, 18.4.303, 19.2.098, 19.1.0, 19.0.1a, 19.2.099, 18.3.7, 19.2.097, 18.3.1, 19.2.0, 18.3.4, 18.2.0, 18.4.1, 18.4.0, 18.3.5, 18.3.3, 18.3.0, 19.2.3, 20.3.1, 20.1.2, 19.2.929, 19.2.31, 20.3.2, 19.2.32, 18.4.6, 20.4.1, 19.2.4, 20.4.1.1, 20.3.3, 20.5.1, 20.1.3, 20.4.1.2, 20.4.2, 20.3.4, 20.6.1, 20.6.2, 20.7.1, 20.3.5, 20.6.3, 20.8.1, 20.7.2, 20.6.4, 20.9.1, 20.3.6, 20.9.1.1, 20.9.2, 20.6.5, 20.3.7, 20.9.3, 20.4.2.3, 20.3.4.3, 20.6.4.1, 20.6.3.2, 20.3.5.1, 20.9.3.1, 20.6.5.2, 20.3.7.1, 20.3.3.2, 20.6.1.2, 20.1.3.1, 20.9.2.2, 20.6.5.3, 20.6.3.3, 20.3.7.2, 20.6.5.4, 20.9.2.3, 20.3.8, 19.0.0, 19.1.01, 20.1.11, 20.7.1.2, 20.6.5.1

Timeline

Official Publish: September 25th, 2024
Last Modified: September 25th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

Weaknesses (CWE)