HIGH · 7.4

CVE-2025-20140

A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial ...

Vulnerability Description

A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of IPv6 network requests from an associated wireless IPv6 client to an affected device. To associate a client to a device, an attacker may first need to authenticate to the network, or associate freely in the case of a configured open network. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to stop responding, resulting in a DoS condition.

CVSS Score

7.4

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoIos Xe16.4.1
CiscoCatalyst 9800-Cl Wireless Controllers For CloudAll versions
CiscoCatalyst 9105Axi-
CiscoCatalyst 9115Axe-
CiscoCatalyst 9115Axi-
CiscoCatalyst 9117Axi-
CiscoCatalyst 9120Axe-
CiscoCatalyst 9120Axi-
CiscoCatalyst 9120Axp-
CiscoCatalyst 9130Axe-
CiscoCatalyst 9130Axi-
CiscoCatalyst 9800-40-
CiscoCatalyst 9800-80-
CiscoCatalyst 9800-L-
CiscoCatalyst Cw9800H1-
CiscoCatalyst Cw9800H2-
CiscoCatalyst Cw9800M-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-20140?

CVE-2025-20140 is a vulnerability with a CVSS score of 7.4 (HIGH). A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial ...

How severe is CVE-2025-20140?

CVE-2025-20140 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-20140?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xe, Cisco Catalyst 9800-Cl Wireless Controllers For Cloud, Cisco Catalyst 9105Axi, Cisco Catalyst 9115Axe, Cisco Catalyst 9115Axi.