CVE-2024-20294 is a medium-severity denial-of-service vulnerability affecting Cisco FXOS and NX-OS Software's Link Layer Discovery Protocol (LLDP) feature. An unauthenticated, adjacent attacker can exploit this by sending a crafted LLDP packet to an affected device, potentially causing the LLDP service to crash and, in some cases, trigger a device reload. The attack requires physical or logical adjacency and user interaction to retrieve LLDP statistics. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.1.63CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.1.63:*:*:*:*:*:*:* | ||
2.2.1.66CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.1.66:*:*:*:*:*:*:* | ||
2.2.1.70CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.1.70:*:*:*:*:*:*:* | ||
2.2.2.17CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.17:*:*:*:*:*:*:* | ||
2.2.2.19CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_extensible_operating_system:2.2.2.19:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.