A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of certain L2TP packets. An attacker could exploit this vulnerability by sending crafted L2TP packets to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.
Note: Only traffic directed to the affected system can be used to exploit this vulnerability.
This vulnerability is due to improper handling of certain L2TP packets. An attacker could exploit this vulnerability by sending crafted L2TP packets to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.
Note: Only traffic directed to the affected system can be used to exploit this vulnerability.
Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Changed
Confidentiality Impact None
Integrity Impact None
Availability Impact High
User Interaction None
No CVSS v3.0
No CVSS v2
This CVE is not in the KEV list.
The EPSS score is 0.0047.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
1000 Integrated Services Router
Subscribe
1100-4g Integrated Services Router
Subscribe
1100-4gltegb Integrated Services Router
Subscribe
1100-4gltena Integrated Services Router
Subscribe
1100-6g Integrated Services Router
Subscribe
4221 Integrated Services Router
Subscribe
4321\/k9-rf Integrated Services Router
Subscribe
4321\/k9-ws Integrated Services Router
Subscribe
4321\/k9 Integrated Services Router
Subscribe
4321 Integrated Services Router
Subscribe
4331\/k9-rf Integrated Services Router
Subscribe
4331\/k9-ws Integrated Services Router
Subscribe
4331\/k9 Integrated Services Router
Subscribe
4331 Integrated Services Router
Subscribe
4351\/k9-rf Integrated Services Router
Subscribe
4351\/k9-ws Integrated Services Router
Subscribe
4351\/k9 Integrated Services Router
Subscribe
4351 Integrated Services Router
Subscribe
4431 Integrated Services Router
Subscribe
4451 Integrated Services Router
Subscribe
4461 Integrated Services Router
Subscribe
C8200-1n-4t
Subscribe
C8200l-1n-4t
Subscribe
C8500l-8s4x
Subscribe
Catalyst 8000v Edge
Subscribe
Catalyst 8300-1n1s-4t2x
Subscribe
Catalyst 8300-1n1s-6t
Subscribe
Catalyst 8300-2n2s-4t2x
Subscribe
Catalyst 8300-2n2s-6t
Subscribe
Cloud Services Router 1000v
Subscribe
Ios Xe
Subscribe
Vg400-2fxs\/2fxo
Subscribe
Vg400-4fxs\/4fxo
Subscribe
Vg400-6fxs\/6fxo
Subscribe
Vg400-8fxs
Subscribe
Vg420-132fxs\/6fxo
Subscribe
Vg420-144fxs
Subscribe
Vg420-84fxs\/6fxo
Subscribe
Vg450-144fxs\/k9
Subscribe
Vg450-72fxs\/k9
Subscribe
Vg450\/k9
Subscribe
|
Configuration 1 [-]
| AND |
|
No data.
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24406 | A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain L2TP packets. An attacker could exploit this vulnerability by sending crafted L2TP packets to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-08-02T09:05:35.876Z
Reserved: 2022-10-27T18:47:50.369Z
Link: CVE-2023-20227
No data.
Status : Modified
Published: 2023-09-27T18:15:11.370
Modified: 2024-11-21T07:40:56.480
Link: CVE-2023-20227
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD