CVE-2024-20354: High severity cisco access point software vulnerability
A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed frames. An attacker could exploit this vulnerability by connecting as a wireless client to an affected AP and sending specific malformed frames over the wireless connection. A successful exploit could allow the attacker to cause degradation of service to other clients, which could potentially lead to a complete DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20354?
CVE-2024-20354 is classified as a high severity vulnerability due to its potential to cause a denial of service condition.
How do I fix CVE-2024-20354?
To mitigate CVE-2024-20354, it is recommended to apply the latest security updates provided by Cisco for Aironet Access Point Software.
Who is affected by CVE-2024-20354?
CVE-2024-20354 affects users of Cisco Aironet Access Point Software that have not applied recent security patches.
What types of attacks can CVE-2024-20354 facilitate?
CVE-2024-20354 can enable unauthenticated adjacent attackers to cause a denial of service on affected Cisco Aironet access points.
Is user intervention needed to exploit CVE-2024-20354?
No user intervention is needed to exploit CVE-2024-20354, as it can be triggered by an adjacent attacker without authentication.