A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error and improper management of resources related to the handling of CAPWAP Mobility messages. An attacker could exploit this vulnerability by sending crafted CAPWAP Mobility packets to an affected device. A successful exploit could allow the attacker to exhaust resources on the affected device. This would cause the device to reload, resulting in a DoS condition.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HCisco Catalyst 9800
HWCiscowszystkie wersjeCisco Catalyst 9800 40
HWCiscowszystkie wersjeCisco Catalyst 9800 80
HWCiscowszystkie wersjeCisco Catalyst 9800 Cl
HWCiscowszystkie wersjeCisco Catalyst 9800 L
HWCiscowszystkie wersjeCisco Catalyst 9800 L C
HWCiscowszystkie wersjeCisco Catalyst 9800 L F
HWCiscowszystkie wersjeCisco IOS XE
OSCisco17.3.4c
Powiązane podatności
Cisco IOS XE Web UI — nieautoryzowane tworzenie konta z privilege 15
Buffer overflow w QoS Cisco IOS/IOS XE — RCE i DoS przez UDP 18999
RCE w Cisco IOS/IOS XE – podatność protokołu CMP przez Telnet
Nieprawidłowa kontrola dostępu w Cisco IOS XE Software (CVE-2026-20267)
Cisco IOS XE — improper neutralization of special elements (CWE-74)