A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device.
This vulnerability is due to incomplete cleanup of resources when dropping certain malformed frames. An attacker could exploit this vulnerability by connecting as a wireless client to an affected AP and sending specific malformed frames over the wireless connection. A successful exploit could allow the attacker to cause degradation of service to other clients, which could potentially lead to a complete DoS condition.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
13 Aug 2025, 17:18
Type | Values Removed | Values Added |
---|---|---|
First Time |
Cisco wireless Lan Controller Software
Cisco aironet 2700i Cisco ap801 Cisco aironet 1552h Cisco iw3700 Cisco aironet 1552wu Cisco aironet 1530i Cisco ap803 Cisco ios Xe Cisco aironet 2700e Cisco aironet 3700e Cisco aironet 1552s Cisco aironet 1700i Cisco aironet 1530e Cisco Cisco ap802 Cisco aironet 3700i Cisco aironet 3700p |
|
References | () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-airo-ap-dos-PPPtcVW - Vendor Advisory | |
CPE | cpe:2.3:a:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_2700i:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:iw3700:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_3700i:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_2700e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_1530i:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_3700p:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_1552h:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_1552wu:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ap802:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_3700e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_1700i:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_1530e:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* cpe:2.3:h:cisco:ap803:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:aironet_1552s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:ap801:-:*:*:*:*:*:*:* |
21 Nov 2024, 08:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-airo-ap-dos-PPPtcVW - |
27 Mar 2024, 17:48
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-27 17:15
Updated : 2025-08-13 17:18
NVD link : CVE-2024-20354
Mitre link : CVE-2024-20354
CVE.ORG link : CVE-2024-20354
JSON object : View
Products Affected
cisco
- aironet_2700i
- ap801
- ios_xe
- aironet_1552wu
- iw3700
- aironet_2700e
- ap802
- aironet_1530e
- aironet_1530i
- aironet_1552s
- aironet_1700i
- aironet_3700p
- aironet_3700i
- aironet_3700e
- ap803
- aironet_1552h
- wireless_lan_controller_software
CWE
CWE-460
Improper Cleanup on Thrown Exception