CVE-2020-3486
Summary
| CVE | CVE-2020-3486 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-24 18:15:00 UTC |
| Updated | 2021-10-19 18:44:00 UTC |
| Description | Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could exploit these vulnerabilities by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition on the affected device. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Catalyst 9105 | - | All | All | All |
| Hardware | Cisco | Catalyst 9105 | - | All | All | All |
| Hardware | Cisco | Catalyst 9115 | - | All | All | All |
| Hardware | Cisco | Catalyst 9115 | - | All | All | All |
| Hardware | Cisco | Catalyst 9117 | - | All | All | All |
| Hardware | Cisco | Catalyst 9117 | - | All | All | All |
| Hardware | Cisco | Catalyst 9120 | - | All | All | All |
| Hardware | Cisco | Catalyst 9120 | - | All | All | All |
| Hardware | Cisco | Catalyst 9130 | - | All | All | All |
| Hardware | Cisco | Catalyst 9130 | - | All | All | All |
| Hardware | Cisco | Catalyst 9800-40 | - | All | All | All |
| Hardware | Cisco | Catalyst 9800-40 | - | All | All | All |
| Hardware | Cisco | Catalyst 9800-80 | - | All | All | All |
| Hardware | Cisco | Catalyst 9800-80 | - | All | All | All |
| Hardware | Cisco | Catalyst 9800-cl | - | All | All | All |
| Hardware | Cisco | Catalyst 9800-cl | - | All | All | All |
| Hardware | Cisco | Catalyst 9800-l | - | All | All | All |
| Hardware | Cisco | Catalyst 9800-l | - | All | All | All |
| Hardware | Cisco | Catalyst 9800 Embedded Wireless Controller | - | All | All | All |
| Hardware | Cisco | Catalyst 9800 Embedded Wireless Controller | - | All | All | All |
| Operating System | Cisco | Ios Xe | - | All | All | All |
| Operating System | Cisco | Ios Xe | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerabilities | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.