A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device.
This vulnerability is due to incomplete cleanup of resources when dropping certain malformed frames. An attacker could exploit this vulnerability by connecting as a wireless client to an affected AP and sending specific malformed frames over the wireless connection. A successful exploit could allow the attacker to cause degradation of service to other clients, which could potentially lead to a complete DoS condition.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
13 Aug 2025, 17:18
Type | Values Removed | Values Added |
---|---|---|
First Time |
Cisco ap801
Cisco aironet 2700i Cisco wireless Lan Controller Software Cisco aironet 3700i Cisco aironet 1530i Cisco aironet 1700i Cisco aironet 3700e Cisco aironet 1552h Cisco aironet 1552wu Cisco aironet 2700e Cisco ap802 Cisco Cisco aironet 1552s Cisco ap803 Cisco iw3700 Cisco ios Xe Cisco aironet 3700p Cisco aironet 1530e |
|
CPE | cpe:2.3:h:cisco:aironet_1552s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_2700i:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_3700i:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ap801:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ap803:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* cpe:2.3:a:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_2700e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ap802:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_1530i:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_1552h:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:iw3700:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_3700p:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_1700i:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_1552wu:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_1530e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_3700e:-:*:*:*:*:*:*:* |
|
References | () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-airo-ap-dos-PPPtcVW - Vendor Advisory |
Information
Published : 2024-03-27 17:15
Updated : 2025-08-13 17:18
NVD link : CVE-2024-20354
Mitre link : CVE-2024-20354
CVE.ORG link : CVE-2024-20354
JSON object : View
Products Affected
cisco
- aironet_2700i
- aironet_1530i
- aironet_3700e
- ap802
- aironet_1552h
- wireless_lan_controller_software
- aironet_1552wu
- aironet_3700p
- aironet_1530e
- ap801
- aironet_1700i
- aironet_3700i
- ap803
- aironet_2700e
- aironet_1552s
- iw3700
- ios_xe
CWE
CWE-460
Improper Cleanup on Thrown Exception