PT-2020-4164 · Cisco · Cisco Ios Xe Wireless Controller+1
Published
2020-09-24
·
Updated
2023-05-22
·
CVE-2020-3428
CVSS v3.1
7.4
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family (affected versions not specified)
Description:
A vulnerability in the WLAN Local Profiling feature could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The issue is due to incorrect parsing of HTTP packets while performing HTTP-based endpoint device classifications. An attacker could exploit this by sending a crafted HTTP packet to an affected device, potentially causing it to reboot and resulting in a DoS condition.
Recommendations:
For Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family, update to a version that includes the software updates released by Cisco to address this vulnerability.
As a temporary workaround, consider disabling the WLAN Local Profiling feature, as it is disabled by default, to minimize the risk of exploitation.
Fix
DoS
Resource Exhaustion
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios Xe Wireless Controller
Cisco Ios Xe