CVE-2024-20354: High severity cisco access point software vulnerability

Published Mar 27, 2024
·
Updated

A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed frames. An attacker could exploit this vulnerability by connecting as a wireless client to an affected AP and sending specific malformed frames over the wireless connection. A successful exploit could allow the attacker to cause degradation of service to other clients, which could potentially lead to a complete DoS condition.

Affected Software

38 affected components
Cisco Aironet Access Point Software
All of the following
Any of the following
Cisco Wireless LAN Controller Software>=8.5.171.0<8.6.0.0
Cisco Wireless LAN Controller Software>=8.10.130.0<8.10.190.81
Any of the following
Cisco Aironet 1530e
Cisco Aironet 1530i
Cisco Aironet 1552h
Cisco Aironet 1552s
Cisco Aironet 1552wu
Cisco Aironet 1700i
Cisco Aironet 2700e
Cisco Aironet 2700i
Cisco Aironet 3700e
Cisco Aironet 3700i
Cisco Aironet 3700p
Cisco Ap801
Cisco Ap802
Cisco Ap803
Cisco Iw3700
All of the following
Any of the following
Cisco IOS XE>=16.12.4a<17.1.0
Cisco IOS XE>=17.3.0<17.3.9
Cisco IOS XE>=17.4.0<17.6.7
Cisco IOS XE>=17.7.0<17.9.5
Cisco IOS XE>=17.10.0<17.12.2
Any of the following
Cisco Aironet 1530e
Cisco Aironet 1530i
Cisco Aironet 1552h
Cisco Aironet 1552s
Cisco Aironet 1552wu
Cisco Aironet 1700i
Cisco Aironet 2700e
Cisco Aironet 2700i
Cisco Aironet 3700e
Cisco Aironet 3700i
Cisco Aironet 3700p
Cisco Ap801
Cisco Ap802
Cisco Ap803
Cisco Iw3700

Event History

Mar 27, 2024
CVE Published
via MITRE·04:47 PM
Data Sourced
via MITRE·04:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-20354?

CVE-2024-20354 is classified as a high severity vulnerability due to its potential to cause a denial of service condition.

2

How do I fix CVE-2024-20354?

To mitigate CVE-2024-20354, it is recommended to apply the latest security updates provided by Cisco for Aironet Access Point Software.

3

Who is affected by CVE-2024-20354?

CVE-2024-20354 affects users of Cisco Aironet Access Point Software that have not applied recent security patches.

4

What types of attacks can CVE-2024-20354 facilitate?

CVE-2024-20354 can enable unauthenticated adjacent attackers to cause a denial of service on affected Cisco Aironet access points.

5

Is user intervention needed to exploit CVE-2024-20354?

No user intervention is needed to exploit CVE-2024-20354, as it can be triggered by an adjacent attacker without authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203