Cisco Access Point Software Vulnerability Could Lead to Denial of Service
CVE-2024-20271
Summary
A vulnerability in the IP packet processing of Cisco Access Point Software allows an unauthenticated, remote attacker to exploit specific weaknesses in input validation of IPv4 packets. By sending specially crafted IPv4 packets to or through an affected device, an attacker can induce an unexpected reload of the device, resulting in a denial of service (DoS) condition. Importantly, exploitation does not require the attacker to be associated with the access point, making this a significant risk to network availability. This issue does not affect IPv6 packet processing.
Affected Version(s)
Cisco Aironet Access Point Software 8.2.100.0
Cisco Aironet Access Point Software 8.2.130.0
Cisco Aironet Access Point Software 8.2.111.0
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved