PT-2022-6094 · Cisco · Cisco Wireless Lan Controller+1

Published

2022-09-28

·

Updated

2022-10-04

·

CVE-2022-20769

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Wireless LAN Controller (WLC) AireOS Software (affected versions not specified)
Description The issue is related to insufficient error validation in the authentication functionality of the Cisco Wireless LAN Controller, which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. An attacker could exploit this by sending crafted packets to the device, potentially causing it to crash. This vulnerability affects devices with Federal Information Processing Standards (FIPS) mode enabled.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-00032
CVE-2022-20769

Affected Products

Cisco Wireless Lan Controller
Cisco Wls