CVE-2020-3390

CVSS 3.1 Score 7.4 of 10 (high)

Details

Published Sep 24, 2020
Updated: Dec 19, 2024
CWE ID 20

Summary

CVE-2020-3390 is a denial-of-service vulnerability impacting the Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family. An unauthenticated attacker in close proximity to an affected device can exploit this issue by sending a maliciously crafted 802.1x packet during the wireless authentication setup phase. The vulnerability stems from insufficient input validation of SNMP trap data related to wireless client connections. Successful exploitation allows the attacker to trigger an unexpected device reload, resulting in a denial-of-service condition.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco IOS-XE

Affected Vendors

  • Cisco Systems Inc