CVE-2021-1565
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 4.0
Source: NVD
Description
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit the vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition.
Affected (9)
Products: Cisco: Ios Xe, Embedded Wireless Controller, Catalyst 9800 Firmware
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst 9300 24p A | All versions |
Cisco Catalyst 9300 24p E | All versions |
Cisco Catalyst 9300 24s A | All versions |
Cisco Catalyst 9300 24s E | All versions |
Cisco Catalyst 9300 24t A | All versions |
Cisco Catalyst 9300 24t E | All versions |
Cisco Catalyst 9300 24u A | All versions |
Cisco Catalyst 9300 24u E | All versions |
Cisco Catalyst 9300 24ux A | All versions |
Cisco Catalyst 9300 24ux E | All versions |
Cisco Catalyst 9300 48p A | All versions |
Cisco Catalyst 9300 48p E | All versions |
Cisco Catalyst 9300 48s A | All versions |
Cisco Catalyst 9300 48s E | All versions |
Cisco Catalyst 9300 48t A | All versions |
Cisco Catalyst 9300 48t E | All versions |
Cisco Catalyst 9300 48u A | All versions |
Cisco Catalyst 9300 48u E | All versions |
Cisco Catalyst 9300 48un A | All versions |
Cisco Catalyst 9300 48un E | All versions |
Cisco Catalyst 9300 48uxm A | All versions |
Cisco Catalyst 9300 48uxm E | All versions |
Cisco Catalyst 9300l | All versions |
Cisco Catalyst 9300l 24p 4g A | All versions |
Cisco Catalyst 9300l 24p 4g E | All versions |
Cisco Catalyst 9300l 24p 4x A | All versions |
Cisco Catalyst 9300l 24p 4x E | All versions |
Cisco Catalyst 9300l 24t 4g A | All versions |
Cisco Catalyst 9300l 24t 4g E | All versions |
Cisco Catalyst 9300l 24t 4x A | All versions |
Cisco Catalyst 9300l 24t 4x E | All versions |
Cisco Catalyst 9300l 48p 4g A | All versions |
Cisco Catalyst 9300l 48p 4g E | All versions |
Cisco Catalyst 9300l 48p 4x A | All versions |
Cisco Catalyst 9300l 48p 4x E | All versions |
Cisco Catalyst 9300l 48t 4g A | All versions |
Cisco Catalyst 9300l 48t 4g E | All versions |
Cisco Catalyst 9300l 48t 4x A | All versions |
Cisco Catalyst 9300l 48t 4x E | All versions |
Cisco Catalyst 9300l Stack | All versions |
Cisco Catalyst 9400 | All versions |
Cisco Catalyst 9400 Supervisor Engine 1 | All versions |
Cisco Catalyst 9407r | All versions |
Cisco Catalyst 9410r | All versions |
Cisco Catalyst 9500 | All versions |
Configuration C
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst 9800 40 | All versions |
Cisco Catalyst 9800 80 | All versions |
Cisco Catalyst 9800 L | All versions |
Cisco Catalyst 9800 L C | All versions |
Cisco Catalyst 9800 L F | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 17.3 |
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst 9800 Cl | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.