Vulnerability Description
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of IPv6 network requests from an associated wireless IPv6 client to an affected device. To associate a client to a device, an attacker may first need to authenticate to the network, or associate freely in the case of a configured open network. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to stop responding, resulting in a DoS condition.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 16.4.1 |
| Cisco | Catalyst 9800-Cl Wireless Controllers For Cloud | All versions |
| Cisco | Catalyst 9105Axi | - |
| Cisco | Catalyst 9115Axe | - |
| Cisco | Catalyst 9115Axi | - |
| Cisco | Catalyst 9117Axi | - |
| Cisco | Catalyst 9120Axe | - |
| Cisco | Catalyst 9120Axi | - |
| Cisco | Catalyst 9120Axp | - |
| Cisco | Catalyst 9130Axe | - |
| Cisco | Catalyst 9130Axi | - |
| Cisco | Catalyst 9800-40 | - |
| Cisco | Catalyst 9800-80 | - |
| Cisco | Catalyst 9800-L | - |
| Cisco | Catalyst Cw9800H1 | - |
| Cisco | Catalyst Cw9800H2 | - |
| Cisco | Catalyst Cw9800M | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-20140?
CVE-2025-20140 is a vulnerability with a CVSS score of 7.4 (HIGH). A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial ...
How severe is CVE-2025-20140?
CVE-2025-20140 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-20140?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xe, Cisco Catalyst 9800-Cl Wireless Controllers For Cloud, Cisco Catalyst 9105Axi, Cisco Catalyst 9115Axe, Cisco Catalyst 9115Axi.