CVE-2022-20769: Cisco Wireless LAN Controller AireOS Software FIPS Mode Denial of Service Vulnerability
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error validation. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to cause the wireless LAN controller to crash, resulting in a DoS condition. Note: This vulnerability affects only devices that have Federal Information Processing Standards (FIPS) mode enabled.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-20769?
CVE-2022-20769 is a vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software that could allow an unauthenticated attacker to cause a denial of service (DoS) condition on an affected device.
How does CVE-2022-20769 impact Cisco Wireless LAN Controller (WLC) AireOS Software?
CVE-2022-20769 could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
What is the severity of CVE-2022-20769?
CVE-2022-20769 has a severity rating of 6.5 (High).
Is Cisco Virtual Wireless Controller affected by CVE-2022-20769?
No, Cisco Virtual Wireless Controller is not affected by CVE-2022-20769.
How can I fix CVE-2022-20769?
Cisco has released software updates to address CVE-2022-20769. It is recommended to update to the latest version of Cisco Wireless LAN Controller (WLC) AireOS Software.