CVE-2024-20474
MEDIUMDescription
A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by sending a crafted IKEv2 packet to an affected system. A successful exploit could allow the attacker to cause Cisco Secure Client Software to crash, resulting in a DoS condition on the client software. Note: Cisco Secure Client Software releases 4.10 and earlier were known as Cisco AnyConnect Secure Mobility Client.
Is your site exposed to CVE-2024-20474?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | anyconnect_secure_mobility_client |
| cisco | anyconnect_secure_mobility_client |
| cisco | anyconnect_secure_mobility_client |
| cisco | anyconnect_secure_mobility_client |
| cisco | anyconnect_secure_mobility_client |
| cisco | anyconnect_secure_mobility_client |
| cisco | anyconnect_secure_mobility_client |
| cisco | anyconnect_secure_mobility_client |
| cisco | anyconnect_secure_mobility_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
| cisco | secure_client |
References
Frequently Asked Questions
What is CVE-2024-20474? +
How severe is CVE-2024-20474? +
What products are affected by CVE-2024-20474? +
How do I check if I'm vulnerable to CVE-2024-20474? +
Related Vulnerabilities
An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerability by sending a crafted …
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the ESP32-P4 uses …
pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior to 0.2.0-alpha, a …
Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from …
gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data …
Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer …