CVE-2024-20271

HIGH
Published Mar 27, 2024 Modified Aug 6, 2025 CWE-20

Description

A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this vulnerability by sending a crafted IPv4 packet either to or through an affected device. A successful exploit could allow the attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To successfully exploit this vulnerability, the attacker does not need to be associated with the affected AP. This vulnerability cannot be exploited by sending IPv6 packets.

Is your site exposed to CVE-2024-20271?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

8.6
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Weakness Type (CWE)

CWE-20 Improper Input Validation

Affected Products

Vendor Product
cisco ios_xe
cisco ios_xe
cisco ios_xe
cisco ios_xe
cisco business_access_points
cisco business_140ac
cisco business_140ac_access_point
cisco business_141acm
cisco business_142acm
cisco business_143acm
cisco business_145ac
cisco business_145ac_access_point
cisco business_240ac
cisco business_access_points
cisco business_150ax
cisco business_150ax_access_point
cisco business_151axm
cisco wireless_lan_controller_software

References

Frequently Asked Questions

What is CVE-2024-20271? +
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this vulnerability by sending a crafted IPv4 packet either to or through an affected device. A successful exploit could allow the attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To successfully exploit this vulnerability, the attacker does not need to be associated with the affected AP. This vulnerability cannot be exploited by sending IPv6 packets. It has a CVSS v3.1 base score of 8.6 (HIGH).
How severe is CVE-2024-20271? +
CVE-2024-20271 has a CVSS v3.1 score of 8.6 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-20271? +
CVE-2024-20271 affects products from cisco, specifically: business_140ac, business_140ac_access_point, business_141acm, business_142acm, business_143acm, business_145ac, business_145ac_access_point, business_150ax, business_150ax_access_point, business_151axm, business_240ac, business_access_points, ios_xe, wireless_lan_controller_software. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-20271? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-20271 — free, no signup required.