CVE-2024-20294
Cisco Nx-Os 10.1\(1\) … 9.3\(9\)
Raw vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:HSummary
CVE-2024-20294 is a medium-severity Buffer Access with Incorrect Length Value (CWE-805) vulnerability in Cisco Nx-Os. Its CVSS base score is 6.6 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked at the 24th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SA-11 (Developer Testing and Evaluation) and SA-8 (Security and Privacy Engineering Principles) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-18009
Vulnerability Data
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due…
more
to improper handling of specific fields in an LLDP frame. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface of an affected device and having an authenticated user retrieve LLDP statistics from the affected device through CLI show commands or Simple Network Management Protocol (SNMP) requests. A successful exploit could allow the attacker to cause the LLDP service to crash and stop running on the affected device. In certain situations, the LLDP crash may result in a reload of the affected device. Note: LLDP is a Layer 2 link protocol. To exploit this vulnerability, an attacker would need to be directly connected to an interface of an affected device, either physically or logically (for example, through a Layer 2 Tunnel configured to transport the LLDP protocol).
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V1.4.1
Mitigating Controls (NIST 800-53 r5) AI
Developer testing and evaluation (including fuzzing and static analysis) directly finds incorrect length values used in sequential buffer accesses.
Secure engineering principles require explicit bounds checking and correct length calculations when performing buffer operations.
Input validation rejects or corrects malformed length values supplied from external sources before they reach buffer operations.
Memory protection mechanisms limit the blast radius when an incorrect length value causes an out-of-bounds access.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development can detect out-of-bounds accesses, but does not guarantee prevention.
Secure development life cycle mandates buffer-safety practices that directly prevent incorrect length values.
Application security requirements can specify buffer-size validation, but do not prescribe implementation details.
Secure architecture principles encourage bounds-checked APIs, yet leave concrete coding decisions to developers.
Secure coding explicitly requires correct buffer-length handling, eliminating CWE-805 when followed.