CVE-2020-3559
HIGHCisco WLC & Aironet AP Software - Unauthenticated DoS via Auth Request Flood
Title source: llmDescription
A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper handling of clients that are trying to connect to the AP. An attacker could exploit this vulnerability by sending authentication requests from multiple clients to an affected device. A successful exploit could allow the attacker to cause the affected device to reload.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aironet-dos-h3DCuLXw
Scores
CVSS v3
8.6
EPSS
0.0128
EPSS Percentile
79.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (5)
cisco/access_points
< 16.12.4a
cisco/aironet_access_point_software
8.5\(151.0\)
cisco/aironet_access_point_software
17.2.0.26
cisco/business_access_points
10.0 - 10.1.1.0
cisco/wireless_lan_controller
8.9 - 8.10.112.0
Published
Sep 24, 2020
Tracked Since
Feb 18, 2026