CVE-2020-3260
MEDIUMCisco Aironet Series Access Points - Unauthenticated Denial of Service via Client Packet Processing
Title source: llmDescription
A vulnerability in Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper processing of client packets that are sent to an affected access point (AP). An attacker could exploit this vulnerability by sending a large number of sustained client packets to the affected AP. A successful exploit could allow the attacker to cause the affected AP to crash, resulting in a DoS condition.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-airo-wpa-dos-5ZLs6ESz
Scores
CVSS v3
6.5
EPSS
0.0031
EPSS Percentile
54.2%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-399
CWE-400
Status
published
Products (6)
cisco/aironet_1542d_firmware
8.9\(100.0\)
cisco/aironet_1542i_firmware
8.9\(100.0\)
cisco/aironet_1815_firmware
8.9\(100.0\)
cisco/aironet_1830_firmware
8.9\(100.0\)
cisco/aironet_1840_firmware
8.9\(100.0\)
cisco/aironet_1850_firmware
8.9\(100.0\)
Published
Apr 15, 2020
Tracked Since
Feb 18, 2026