IT

Tracker / CVE-2020-3552

CVE-2020-3552

High 7.4

A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by connecting as a wired client to the Ethernet interface of an affected device and sending a series of specific packets within a short time frame. A successful exploit could allow the attacker to cause a NULL pointer access that results in a reload of the affected device.

Affected products and versions

cisco access_points · … → 16.12.4a
cisco aironet_access_point_software
cisco business_access_points · 10.0 → 10.1.1.0
cisco wireless_lan_controller · 8.6 → 8.10.105.0

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References