CVE-2024-20354
MEDIUMDescription
A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed frames. An attacker could exploit this vulnerability by connecting as a wireless client to an affected AP and sending specific malformed frames over the wireless connection. A successful exploit could allow the attacker to cause degradation of service to other clients, which could potentially lead to a complete DoS condition.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | wireless_lan_controller_software |
| cisco | wireless_lan_controller_software |
| cisco | aironet_1530e |
| cisco | aironet_1530i |
| cisco | aironet_1552h |
| cisco | aironet_1552s |
| cisco | aironet_1552wu |
| cisco | aironet_1700i |
| cisco | aironet_2700e |
| cisco | aironet_2700i |
| cisco | aironet_3700e |
| cisco | aironet_3700i |
| cisco | aironet_3700p |
| cisco | ap801 |
| cisco | ap802 |
| cisco | ap803 |
| cisco | iw3700 |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | ios_xe |
| cisco | aironet_1530e |
| cisco | aironet_1530i |
| cisco | aironet_1552h |
| cisco | aironet_1552s |
| cisco | aironet_1552wu |
| cisco | aironet_1700i |
| cisco | aironet_2700e |
| cisco | aironet_2700i |
| cisco | aironet_3700e |
| cisco | aironet_3700i |
| cisco | aironet_3700p |
| cisco | ap801 |
| cisco | ap802 |
| cisco | ap803 |
| cisco | iw3700 |
References
Frequently Asked Questions
What is CVE-2024-20354? +
How severe is CVE-2024-20354? +
What products are affected by CVE-2024-20354? +
How do I check if I'm vulnerable to CVE-2024-20354? +
Related Vulnerabilities
UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction …
Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to …
Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at …
pleezer is a headless Deezer Connect player. Hook scripts in pleezer can be triggered by various events like track changes …
Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may …
libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error message generation.