CVE-2024-20508
MEDIUMDescription
A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured security policies or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of HTTP requests when they are processed by Cisco UTD Snort IPS Engine. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to trigger a reload of the Snort process. If the action in case of Cisco UTD Snort IPS Engine failure is set to the default, fail-open, successful exploitation of this vulnerability could allow the attacker to bypass configured security policies. If the action in case of Cisco UTD Snort IPS Engine failure is set to fail-close, successful exploitation of this vulnerability could cause traffic that is configured to be inspected by Cisco UTD Snort IPS Engine to be dropped.
Is your site exposed to CVE-2024-20508?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
| cisco | unified_threat_defense_snort_intrusion_prevention_system_engine |
References
Frequently Asked Questions
What is CVE-2024-20508? +
How severe is CVE-2024-20508? +
What products are affected by CVE-2024-20508? +
How do I check if I'm vulnerable to CVE-2024-20508? +
Related Vulnerabilities
vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json). This …
A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for …
A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. …
Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from …
Heap-based Buffer Overflow vulnerability in iniparser_dumpsection_ini() in iniparser allows attacker to read out of bound memory
There is a Heap-based Buffer Overflow vulnerability in QTextMarkdownImporter. This requires an incorrectly formatted markdown file to be passed to …