CVE Vulnerabilities

CVE-2024-20314

Operator Precedence Logic Error

Published: Mar 27, 2024 | Modified: Jul 30, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization and stop all traffic processing, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain IPv4 packets. An attacker could exploit this vulnerability by sending certain IPv4 packets to an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition.

Weakness

The product uses an expression in which operator precedence causes incorrect logic to be used.

Affected Software

NameVendorStart VersionEnd Version
Ios_xeCisco16.1.1 (including)16.1.1 (including)
Ios_xeCisco16.1.2 (including)16.1.2 (including)
Ios_xeCisco16.1.3 (including)16.1.3 (including)
Ios_xeCisco16.2.1 (including)16.2.1 (including)
Ios_xeCisco16.2.2 (including)16.2.2 (including)
Ios_xeCisco16.3.1 (including)16.3.1 (including)
Ios_xeCisco16.3.1a (including)16.3.1a (including)
Ios_xeCisco16.3.2 (including)16.3.2 (including)
Ios_xeCisco16.3.3 (including)16.3.3 (including)
Ios_xeCisco16.3.4 (including)16.3.4 (including)
Ios_xeCisco16.3.5 (including)16.3.5 (including)
Ios_xeCisco16.3.5b (including)16.3.5b (including)
Ios_xeCisco16.3.6 (including)16.3.6 (including)
Ios_xeCisco16.3.7 (including)16.3.7 (including)
Ios_xeCisco16.3.8 (including)16.3.8 (including)
Ios_xeCisco16.3.9 (including)16.3.9 (including)
Ios_xeCisco16.3.10 (including)16.3.10 (including)
Ios_xeCisco16.3.11 (including)16.3.11 (including)
Ios_xeCisco16.4.1 (including)16.4.1 (including)
Ios_xeCisco16.4.2 (including)16.4.2 (including)
Ios_xeCisco16.4.3 (including)16.4.3 (including)
Ios_xeCisco16.5.1 (including)16.5.1 (including)
Ios_xeCisco16.5.1a (including)16.5.1a (including)
Ios_xeCisco16.5.1b (including)16.5.1b (including)
Ios_xeCisco16.5.2 (including)16.5.2 (including)
Ios_xeCisco16.5.3 (including)16.5.3 (including)
Ios_xeCisco16.6.1 (including)16.6.1 (including)
Ios_xeCisco16.6.2 (including)16.6.2 (including)
Ios_xeCisco16.6.3 (including)16.6.3 (including)
Ios_xeCisco16.6.4 (including)16.6.4 (including)
Ios_xeCisco16.6.4a (including)16.6.4a (including)
Ios_xeCisco16.6.5 (including)16.6.5 (including)
Ios_xeCisco16.6.5a (including)16.6.5a (including)
Ios_xeCisco16.6.6 (including)16.6.6 (including)
Ios_xeCisco16.6.7 (including)16.6.7 (including)
Ios_xeCisco16.6.8 (including)16.6.8 (including)
Ios_xeCisco16.6.9 (including)16.6.9 (including)
Ios_xeCisco16.6.10 (including)16.6.10 (including)
Ios_xeCisco16.7.1 (including)16.7.1 (including)
Ios_xeCisco16.7.1a (including)16.7.1a (including)
Ios_xeCisco16.7.1b (including)16.7.1b (including)
Ios_xeCisco16.7.2 (including)16.7.2 (including)
Ios_xeCisco16.7.3 (including)16.7.3 (including)
Ios_xeCisco16.7.4 (including)16.7.4 (including)
Ios_xeCisco16.8.1 (including)16.8.1 (including)
Ios_xeCisco16.8.1a (including)16.8.1a (including)
Ios_xeCisco16.8.1b (including)16.8.1b (including)
Ios_xeCisco16.8.1c (including)16.8.1c (including)
Ios_xeCisco16.8.1d (including)16.8.1d (including)
Ios_xeCisco16.8.1e (including)16.8.1e (including)
Ios_xeCisco16.8.1s (including)16.8.1s (including)
Ios_xeCisco16.8.2 (including)16.8.2 (including)
Ios_xeCisco16.8.3 (including)16.8.3 (including)
Ios_xeCisco16.9.1 (including)16.9.1 (including)
Ios_xeCisco16.9.1a (including)16.9.1a (including)
Ios_xeCisco16.9.1b (including)16.9.1b (including)
Ios_xeCisco16.9.1s (including)16.9.1s (including)
Ios_xeCisco16.9.2 (including)16.9.2 (including)
Ios_xeCisco16.9.3 (including)16.9.3 (including)
Ios_xeCisco16.9.3a (including)16.9.3a (including)
Ios_xeCisco16.9.4 (including)16.9.4 (including)
Ios_xeCisco16.9.5 (including)16.9.5 (including)
Ios_xeCisco16.9.5f (including)16.9.5f (including)
Ios_xeCisco16.9.6 (including)16.9.6 (including)
Ios_xeCisco16.9.7 (including)16.9.7 (including)
Ios_xeCisco16.9.8 (including)16.9.8 (including)
Ios_xeCisco16.10.1 (including)16.10.1 (including)
Ios_xeCisco16.10.1a (including)16.10.1a (including)
Ios_xeCisco16.10.1b (including)16.10.1b (including)
Ios_xeCisco16.10.1c (including)16.10.1c (including)
Ios_xeCisco16.10.1d (including)16.10.1d (including)
Ios_xeCisco16.10.1e (including)16.10.1e (including)
Ios_xeCisco16.10.1f (including)16.10.1f (including)
Ios_xeCisco16.10.1g (including)16.10.1g (including)
Ios_xeCisco16.10.1s (including)16.10.1s (including)
Ios_xeCisco16.10.2 (including)16.10.2 (including)
Ios_xeCisco16.10.3 (including)16.10.3 (including)
Ios_xeCisco16.11.1 (including)16.11.1 (including)
Ios_xeCisco16.11.1a (including)16.11.1a (including)
Ios_xeCisco16.11.1b (including)16.11.1b (including)
Ios_xeCisco16.11.1s (including)16.11.1s (including)
Ios_xeCisco16.11.2 (including)16.11.2 (including)
Ios_xeCisco16.12.1 (including)16.12.1 (including)
Ios_xeCisco16.12.1a (including)16.12.1a (including)
Ios_xeCisco16.12.1c (including)16.12.1c (including)
Ios_xeCisco16.12.1s (including)16.12.1s (including)
Ios_xeCisco16.12.1t (including)16.12.1t (including)
Ios_xeCisco16.12.1w (including)16.12.1w (including)
Ios_xeCisco16.12.1x (including)16.12.1x (including)
Ios_xeCisco16.12.1y (including)16.12.1y (including)
Ios_xeCisco16.12.1z1 (including)16.12.1z1 (including)
Ios_xeCisco16.12.1z2 (including)16.12.1z2 (including)
Ios_xeCisco16.12.2 (including)16.12.2 (including)
Ios_xeCisco16.12.2a (including)16.12.2a (including)
Ios_xeCisco16.12.2s (including)16.12.2s (including)
Ios_xeCisco16.12.3 (including)16.12.3 (including)
Ios_xeCisco16.12.3a (including)16.12.3a (including)
Ios_xeCisco16.12.3s (including)16.12.3s (including)
Ios_xeCisco16.12.4 (including)16.12.4 (including)
Ios_xeCisco16.12.4a (including)16.12.4a (including)
Ios_xeCisco16.12.5 (including)16.12.5 (including)
Ios_xeCisco16.12.5a (including)16.12.5a (including)
Ios_xeCisco16.12.5b (including)16.12.5b (including)
Ios_xeCisco16.12.6 (including)16.12.6 (including)
Ios_xeCisco16.12.6a (including)16.12.6a (including)
Ios_xeCisco16.12.7 (including)16.12.7 (including)
Ios_xeCisco16.12.8 (including)16.12.8 (including)
Ios_xeCisco16.12.9 (including)16.12.9 (including)
Ios_xeCisco16.12.10 (including)16.12.10 (including)
Ios_xeCisco16.12.10a (including)16.12.10a (including)
Ios_xeCisco17.1.1 (including)17.1.1 (including)
Ios_xeCisco17.1.1a (including)17.1.1a (including)
Ios_xeCisco17.1.1s (including)17.1.1s (including)
Ios_xeCisco17.1.1t (including)17.1.1t (including)
Ios_xeCisco17.1.3 (including)17.1.3 (including)
Ios_xeCisco17.2.1 (including)17.2.1 (including)
Ios_xeCisco17.2.1a (including)17.2.1a (including)
Ios_xeCisco17.2.1r (including)17.2.1r (including)
Ios_xeCisco17.2.1v (including)17.2.1v (including)
Ios_xeCisco17.2.2 (including)17.2.2 (including)
Ios_xeCisco17.2.3 (including)17.2.3 (including)
Ios_xeCisco17.3.1 (including)17.3.1 (including)
Ios_xeCisco17.3.1a (including)17.3.1a (including)
Ios_xeCisco17.3.1w (including)17.3.1w (including)
Ios_xeCisco17.3.1x (including)17.3.1x (including)
Ios_xeCisco17.3.1z (including)17.3.1z (including)
Ios_xeCisco17.3.2 (including)17.3.2 (including)
Ios_xeCisco17.3.2a (including)17.3.2a (including)
Ios_xeCisco17.3.3 (including)17.3.3 (including)
Ios_xeCisco17.3.4 (including)17.3.4 (including)
Ios_xeCisco17.3.4a (including)17.3.4a (including)
Ios_xeCisco17.3.4b (including)17.3.4b (including)
Ios_xeCisco17.3.4c (including)17.3.4c (including)
Ios_xeCisco17.3.5 (including)17.3.5 (including)
Ios_xeCisco17.3.5a (including)17.3.5a (including)
Ios_xeCisco17.3.5b (including)17.3.5b (including)
Ios_xeCisco17.3.6 (including)17.3.6 (including)
Ios_xeCisco17.3.7 (including)17.3.7 (including)
Ios_xeCisco17.4.1 (including)17.4.1 (including)
Ios_xeCisco17.4.1a (including)17.4.1a (including)
Ios_xeCisco17.4.1b (including)17.4.1b (including)
Ios_xeCisco17.4.2 (including)17.4.2 (including)
Ios_xeCisco17.4.2a (including)17.4.2a (including)
Ios_xeCisco17.5.1 (including)17.5.1 (including)
Ios_xeCisco17.5.1a (including)17.5.1a (including)
Ios_xeCisco17.6.1 (including)17.6.1 (including)
Ios_xeCisco17.6.1a (including)17.6.1a (including)
Ios_xeCisco17.6.1w (including)17.6.1w (including)
Ios_xeCisco17.6.1x (including)17.6.1x (including)
Ios_xeCisco17.6.1y (including)17.6.1y (including)
Ios_xeCisco17.6.1z (including)17.6.1z (including)
Ios_xeCisco17.6.1z1 (including)17.6.1z1 (including)
Ios_xeCisco17.6.2 (including)17.6.2 (including)
Ios_xeCisco17.6.3 (including)17.6.3 (including)
Ios_xeCisco17.6.3a (including)17.6.3a (including)
Ios_xeCisco17.6.4 (including)17.6.4 (including)
Ios_xeCisco17.6.5 (including)17.6.5 (including)
Ios_xeCisco17.6.5a (including)17.6.5a (including)
Ios_xeCisco17.7.1 (including)17.7.1 (including)
Ios_xeCisco17.7.1a (including)17.7.1a (including)
Ios_xeCisco17.7.1b (including)17.7.1b (including)
Ios_xeCisco17.7.2 (including)17.7.2 (including)
Ios_xeCisco17.8.1 (including)17.8.1 (including)
Ios_xeCisco17.8.1a (including)17.8.1a (including)
Ios_xeCisco17.9.1 (including)17.9.1 (including)
Ios_xeCisco17.9.1a (including)17.9.1a (including)
Ios_xeCisco17.9.1w (including)17.9.1w (including)
Ios_xeCisco17.9.1x (including)17.9.1x (including)
Ios_xeCisco17.9.1x1 (including)17.9.1x1 (including)
Ios_xeCisco17.9.1y (including)17.9.1y (including)
Ios_xeCisco17.9.1y1 (including)17.9.1y1 (including)
Ios_xeCisco17.9.2 (including)17.9.2 (including)
Ios_xeCisco17.9.2a (including)17.9.2a (including)
Ios_xeCisco17.9.3 (including)17.9.3 (including)
Ios_xeCisco17.9.3a (including)17.9.3a (including)
Ios_xeCisco17.9.4 (including)17.9.4 (including)
Ios_xeCisco17.9.4a (including)17.9.4a (including)
Ios_xeCisco17.10.1 (including)17.10.1 (including)
Ios_xeCisco17.10.1a (including)17.10.1a (including)
Ios_xeCisco17.10.1b (including)17.10.1b (including)
Ios_xeCisco17.11.1 (including)17.11.1 (including)
Ios_xeCisco17.11.1a (including)17.11.1a (including)
Ios_xeCisco17.11.99sw (including)17.11.99sw (including)
Ios_xeCisco17.12.1 (including)17.12.1 (including)
Ios_xeCisco17.12.1a (including)17.12.1a (including)
Ios_xeCisco17.12.1w (including)17.12.1w (including)

Potential Mitigations

References