CVE-2024-20390

A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on XML TCP listen port 38751. This vulnerability is due to a lack of proper error validation of ingress XML packets. An attacker could exploit this vulnerability by sending a sustained, crafted stream of XML traffic to a targeted device. A successful exploit could allow the attacker to cause XML TCP port 38751 to become unreachable while the attack traffic persists.
Configurations

Configuration 1 (hide)

cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*

History

07 Oct 2024, 17:51

Type Values Removed Values Added
CWE NVD-CWE-Other
First Time Cisco ios Xr
Cisco
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S - () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-xml-tcpdos-ZEXvrU2S - Vendor Advisory
CPE cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*

12 Sep 2024, 12:35

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en la función Dedicated XML Agent del software Cisco IOS XR podría permitir que un atacante remoto no autenticado provoque una denegación de servicio (DoS) en el puerto de escucha XML TCP 38751. Esta vulnerabilidad se debe a la falta de una validación de errores adecuada de los paquetes XML de entrada. Un atacante podría aprovechar esta vulnerabilidad enviando un flujo continuo y elaborado de tráfico XML a un dispositivo de destino. Una explotación exitosa podría permitir al atacante hacer que el puerto XML TCP 38751 se vuelva inaccesible mientras persista el tráfico de ataque.

11 Sep 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-11 17:15

Updated : 2024-10-07 17:51


NVD link : CVE-2024-20390

Mitre link : CVE-2024-20390

CVE.ORG link : CVE-2024-20390


JSON object : View

Products Affected

cisco

  • ios_xr
CWE
NVD-CWE-Other CWE-940

Improper Verification of Source of a Communication Channel