CVE-2025-20140
7.4
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 4.0
Source: psirt@cisco.com (Secondary)
Description
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition.
This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of IPv6 network requests from an associated wireless IPv6 client to an affected device. To associate a client to a device, an attacker may first need to authenticate to the network, or associate freely in the case of a configured open network. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to stop responding, resulting in a DoS condition.
Affected (194)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 16.10.1 |
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst 9105axi | All versions |
Cisco Catalyst 9115axe | All versions |
Cisco Catalyst 9115axi | All versions |
Cisco Catalyst 9117axi | All versions |
Cisco Catalyst 9120axe | All versions |
Cisco Catalyst 9120axi | All versions |
Cisco Catalyst 9120axp | All versions |
Cisco Catalyst 9130axe | All versions |
Cisco Catalyst 9130axi | All versions |
Cisco Catalyst 9800 40 | All versions |
Cisco Catalyst 9800 80 | All versions |
Cisco Catalyst 9800 Cl Wireless Controllers For Cloud | All versions |
Cisco Catalyst 9800 L | All versions |
Cisco Catalyst Cw9800h1 | All versions |
Cisco Catalyst Cw9800h2 | All versions |
Cisco Catalyst Cw9800m | All versions |
References (1)
Source: psirt@cisco.com
Vendor Advisory
Timeline
No history available yet.