← Back

CVE-2024-20271

nvd nist
Published: Mar 27, 2024Modified: Aug 6, 2025

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this vulnerability by sending a crafted IPv4 packet either to or through an affected device. A successful exploit could allow the attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To successfully exploit this vulnerability, the attacker does not need to be associated with the affected AP. This vulnerability cannot be exploited by sending IPv6 packets.

Affected (7)

3 products
Ios Xe
Business Access Points
Wireless Lan Controller Software
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Before 17.3.8
From 17.10 to 17.12.2
From 17.4 to 17.6.6
From 17.7 to 17.9.5
Configuration B
1 vulnerable · 8 platform
Vulnerable SoftwareAffected Versions
Before 10.9.1.0
Running on/withPlatform Versions
Cisco
Business 140ac
All versions
Cisco
Business 140ac Access Point
All versions
Cisco
Business 141acm
All versions
Cisco
Business 142acm
All versions
Cisco
Business 143acm
All versions
Cisco
Business 145ac
All versions
Cisco
Business 145ac Access Point
All versions
Cisco
Business 240ac
All versions
Configuration C
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Before 10.6.2.0
Running on/withPlatform Versions
Cisco
Business 150ax
All versions
Cisco
Business 150ax Access Point
All versions
Cisco
Business 151axm
All versions
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 8.10.190.0

Timeline

No history available yet.