PT-2020-4164 · Cisco · Cisco Ios Xe Wireless Controller+1

Published

2020-09-24

·

Updated

2023-05-22

·

CVE-2020-3428

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family (affected versions not specified)
Description: A vulnerability in the WLAN Local Profiling feature could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The issue is due to incorrect parsing of HTTP packets while performing HTTP-based endpoint device classifications. An attacker could exploit this by sending a crafted HTTP packet to an affected device, potentially causing it to reboot and resulting in a DoS condition.
Recommendations: For Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family, update to a version that includes the software updates released by Cisco to address this vulnerability. As a temporary workaround, consider disabling the WLAN Local Profiling feature, as it is disabled by default, to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

RCE

Weakness Enumeration

Related Identifiers

BDU:2020-04586
CVE-2020-3428

Affected Products

Cisco Ios Xe Wireless Controller
Cisco Ios Xe