
Proof-of-concept exploit for CVE-2024-20467, a remote denial-of-service vulnerability in Cisco IOS XE Software. Sends crafted fragmented IPv4 packets to trigger device reload on vulnerable routers.
This exploit targets a vulnerability in the IPv4 fragment assembly code found in Cisco IOS XE Software. The vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) condition on vulnerable devices.
An attacker can exploit this vulnerability by sending specially crafted fragmented packets to the target device, either directly or through an interface with virtual fragment reassembly (VFR) enabled. Successful exploitation can cause the device to reload, resulting in a denial of service condition.
Currently, there are no known public proofs of concept or active exploitation cases. However, the potential for using this exploit in real attacks remains.
##DOWNLOAD