PT-2022-6018 · Cisco · Cisco Catalyst 9100 Series Access Points

Javier Contreras

·

Published

2022-09-28

·

Updated

2022-10-05

·

CVE-2022-20945

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Catalyst 9100 Series Access Points (affected versions not specified)
Description A vulnerability in the 802.11 association frame validation could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This issue is due to insufficient input validation of certain parameters within association request frames received by the AP. An attacker could exploit this by sending a crafted 802.11 association request to a nearby device, potentially causing the device to unexpectedly reload and resulting in a DoS condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2022-07469
CVE-2022-20945

Affected Products

Cisco Catalyst 9100 Series Access Points