QID 317238

Date Published: 2022-10-18

QID 317238: Cisco Internetwork Operating System (IOS) XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Mobility Denial of Service (DoS) Vulnerability (cisco-sa-c9800-mob-dos-342YAc6J)

QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command. Affected Products
Catalyst 9800-CL Wireless Controllers for Cloud
Catalyst 9800 Embedded Wireless Controller for Catalyst 9300, 9400, and 9500 Series Switches
Catalyst 9800 Series Wireless Controllers
Note: This QID does not checks for Catalyst 9800 Embedded Wireless Controller


QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.

A successful exploit could allow the attacker to exhaust resources on the affected device.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-c9800-mob-dos-342YAc6J for more information.

    CVEs related to QID 317238

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-c9800-mob-dos-342YAc6J URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-c9800-mob-dos-342YAc6J