PT-2020-4173 · Cisco · Cisco Ios Xe Wireless Controller+1

Published

2020-09-24

·

Updated

2024-12-19

·

CVE-2020-3390

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family (affected versions not specified)
Description: A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients could allow an unauthenticated, adjacent attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition on an affected device. The vulnerability is due to the lack of input validation of the information used to generate an SNMP trap in relation to a wireless client connection. An attacker could exploit this vulnerability by sending an 802.1x packet with crafted parameters during the wireless authentication setup phase of a connection.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the SNMP trap generation for wireless clients to minimize the risk of exploitation. Avoid using crafted parameters during the wireless authentication setup phase of a connection until the issue is resolved.

DoS

RCE

Weakness Enumeration

Related Identifiers

BDU:2020-04595
CVE-2020-3390

Affected Products

Cisco Ios Xe Wireless Controller
Cisco Ios Xe