Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-3262

Опубликовано: 15 апр. 2020
Источник: nvd
CVSS3: 8.6
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol handler of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of CAPWAP packets. An attacker could exploit this vulnerability by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to restart, resulting in a DoS condition.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:cisco:5508_wireless_controller_firmware:8.8\(120.0\):*:*:*:*:*:*:*
cpe:2.3:h:cisco:5508_wireless_controller:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:cisco:5520_wireless_controller_firmware:8.8\(120.0\):*:*:*:*:*:*:*
cpe:2.3:h:cisco:5520_wireless_controller:-:*:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.01407
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol handler of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of CAPWAP packets. An attacker could exploit this vulnerability by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to restart, resulting in a DoS condition.

CVSS3: 8.6
fstec
почти 6 лет назад

Уязвимость реализации протокола Control and Provisioning of Wireless Access Points (CAPWAP) микропрограммного обеспечения контроллеров беспроводного доступа Cisco Wireless LAN Controller (WLC), позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 80%
0.01407
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-20