MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2024-20354

CVSS 4.7v3.1pub. 2024-03-27upd. 2025-08-13

A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed frames. An attacker could exploit this vulnerability by connecting as a wireless client to an affected AP and sending specific malformed frames over the wireless connection. A successful exploit could allow the attacker to cause degradation of service to other clients, which could potentially lead to a complete DoS condition.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
  • Cisco Aironet 1530e

    HW
    Cisco
    all versions
  • Cisco Aironet 1530i

    HW
    Cisco
    all versions
  • Cisco Aironet 1552h

    HW
    Cisco
    all versions
  • Cisco Aironet 1552s

    HW
    Cisco
    all versions
  • Cisco Aironet 1552wu

    HW
    Cisco
    all versions
  • Cisco Aironet 1700i

    HW
    Cisco
    all versions
  • Cisco Aironet 2700e

    HW
    Cisco
    all versions
  • Cisco Aironet 2700i

    HW
    Cisco
    all versions
  • Cisco Aironet 3700e

    HW
    Cisco
    all versions
  • Cisco Aironet 3700i

    HW
    Cisco
    all versions
  • Cisco Aironet 3700p

    HW
    Cisco
    all versions
  • Cisco Ap801

    HW
    Cisco
    all versions
  • Cisco Ap802

    HW
    Cisco
    all versions
  • Cisco Ap803

    HW
    Cisco
    all versions
  • Cisco IOS XE

    OS
    Cisco
    17.10.0 – 17.12.2 (excl.)17.3.0 – 17.3.9 (excl.)17.4.0 – 17.6.7 (excl.)17.7.0 – 17.9.5 (excl.)16.12.4a – 17.1.0 (excl.)
  • Cisco Iw3700

    HW
    Cisco
    all versions
  • Cisco Wireless Lan Controller Software

    APP
    Cisco
    8.10.130.0 – 8.10.190.81 (excl.)8.5.171.0 – 8.6.0.0 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2023-20198CRITICAL10.0⚠ KEVPL ✓same product

Cisco IOS XE Web UI — nieautoryzowane tworzenie konta z privilege 15

CVE-2018-0151CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w QoS Cisco IOS/IOS XE — RCE i DoS przez UDP 18999

CVE-2017-3881CRITICAL9.8⚠ KEVPL ✓same product

RCE w Cisco IOS/IOS XE – podatność protokołu CMP przez Telnet

CVE-2026-20267CRITICAL9.0PL ✓same product

Nieprawidłowa kontrola dostępu w Cisco IOS XE Software (CVE-2026-20267)

CVE-2026-20272CRITICAL9.8PL ✓same product

Cisco IOS XE — improper neutralization of special elements (CWE-74)