CVE-2020-3428
6.5
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
A vulnerability in the WLAN Local Profiling feature of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect parsing of HTTP packets while performing HTTP-based endpoint device classifications. An attacker could exploit this vulnerability by sending a crafted HTTP packet to an affected device. A successful exploit could cause an affected device to reboot, resulting in a DoS condition.
Affected (1)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco 1100 Integrated Services Router | All versions |
Cisco 1101 Integrated Services Router | All versions |
Cisco 1109 Integrated Services Router | All versions |
Cisco 1111x Integrated Services Router | All versions |
Cisco 111x Integrated Services Router | All versions |
Cisco 1120 Integrated Services Router | All versions |
Cisco 1160 Integrated Services Router | All versions |
Cisco 4221 Integrated Services Router | All versions |
Cisco 4321 Integrated Services Router | All versions |
Cisco 4331 Integrated Services Router | All versions |
Cisco 4351 Integrated Services Router | All versions |
Cisco 4431 Integrated Services Router | All versions |
Cisco 4451 X Integrated Services Router | All versions |
Cisco 4461 Integrated Services Router | All versions |
Cisco Asr 1001 Hx | All versions |
Cisco Asr 1001 X | All versions |
Cisco Asr 1002 Hx | All versions |
Cisco Asr 1002 X | All versions |
Cisco Asr 1004 | All versions |
Cisco Asr 1006 | All versions |
Cisco Asr 1006 X | All versions |
Cisco Asr 1009 X | All versions |
Cisco Asr 1013 | All versions |
Cisco Catalyst 9800 40 | All versions |
Cisco Catalyst 9800 80 | All versions |
Cisco Catalyst 9800 Cl | All versions |
Cisco Catalyst 9800 L | All versions |
Cisco Catalyst 9800 L C | All versions |
Cisco Catalyst 9800 L F | All versions |
Cisco Catalyst C9200 24p | All versions |
Cisco Catalyst C9200 24t | All versions |
Cisco Catalyst C9200 48p | All versions |
Cisco Catalyst C9200 48t | All versions |
Cisco Catalyst C9200l 24p 4g | All versions |
Cisco Catalyst C9200l 24p 4x | All versions |
Cisco Catalyst C9200l 24pxg 2y | All versions |
Cisco Catalyst C9200l 24pxg 4x | All versions |
Cisco Catalyst C9200l 24t 4g | All versions |
Cisco Catalyst C9200l 24t 4x | All versions |
Cisco Catalyst C9200l 48p 4g | All versions |
Cisco Catalyst C9300 24p | All versions |
Cisco Catalyst C9300 24s | All versions |
Cisco Catalyst C9300 24t | All versions |
Cisco Catalyst C9300 24u | All versions |
Cisco Catalyst C9300 24ux | All versions |
Cisco Catalyst C9300 48p | All versions |
Cisco Catalyst C9300 48s | All versions |
Cisco Catalyst C9300 48t | All versions |
Cisco Catalyst C9300 48u | All versions |
Cisco Catalyst C9300 48un | All versions |
Cisco Catalyst C9300 48uxm | All versions |
Cisco Catalyst C9300l 24p 4g | All versions |
Cisco Catalyst C9300l 24p 4x | All versions |
Cisco Catalyst C9300l 24t 4g | All versions |
Cisco Catalyst C9300l 24t 4x | All versions |
Cisco Catalyst C9300l 48p 4g | All versions |
Cisco Catalyst C9300l 48p 4x | All versions |
Cisco Catalyst C9300l 48t 4g | All versions |
Cisco Catalyst C9300l 48t 4x | All versions |
Cisco Catalyst C9404r | All versions |
Cisco Catalyst C9407r | All versions |
Cisco Catalyst C9410r | All versions |
Cisco Catalyst C9500 12q | All versions |
Cisco Catalyst C9500 16x | All versions |
Cisco Catalyst C9500 24q | All versions |
Cisco Catalyst C9500 24y4c | All versions |
Cisco Catalyst C9500 32c | All versions |
Cisco Catalyst C9500 32qc | All versions |
Cisco Catalyst C9500 40x | All versions |
Cisco Catalyst C9500 48y4c | All versions |
Cisco Catalyst C9600 Switch | All versions |
Cisco Cloud Services Router 1000v | All versions |
Cisco Integrated Services Virtual Router | All versions |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-400
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.