MEDIUM · 4.7

CVE-2024-20354

A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition ...

Vulnerability Description

A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed frames. An attacker could exploit this vulnerability by connecting as a wireless client to an affected AP and sending specific malformed frames over the wireless connection. A successful exploit could allow the attacker to cause degradation of service to other clients, which could potentially lead to a complete DoS condition.

CVSS Score

4.7

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
CiscoWireless Lan Controller Software>= 8.5.171.0, < 8.6.0.0
CiscoAironet 1530E-
CiscoAironet 1530I-
CiscoAironet 1552H-
CiscoAironet 1552S-
CiscoAironet 1552Wu-
CiscoAironet 1700I-
CiscoAironet 2700E-
CiscoAironet 2700I-
CiscoAironet 3700E-
CiscoAironet 3700I-
CiscoAironet 3700P-
CiscoAp801-
CiscoAp802-
CiscoAp803-
CiscoIw3700-
CiscoIos Xe>= 16.12.4a, < 17.1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-20354?

CVE-2024-20354 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition ...

How severe is CVE-2024-20354?

CVE-2024-20354 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-20354?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Wireless Lan Controller Software, Cisco Aironet 1530E, Cisco Aironet 1530I, Cisco Aironet 1552H, Cisco Aironet 1552S.