CVE-2024-20474
CVSS V2 None
CVSS V3 None
Description
A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client.
This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by sending a crafted IKEv2 packet to an affected system. A successful exploit could allow the attacker to cause Cisco Secure Client Software to crash, resulting in a DoS condition on the client software.
Note: Cisco Secure Client Software releases 4.10 and earlier were known as Cisco AnyConnect Secure Mobility Client.
Overview
- CVE ID
- CVE-2024-20474
- Assigner
- cisco
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-10-23T17:49:23.557Z
- Last Modified Date
- 2024-10-23T20:54:12.513Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csc-dos-XvPhM3bj |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-20474 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20474 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-24 13:26:06 | Added to TrackCVE |