8.6

CVE-2020-3559

A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper handling of clients that are trying to connect to the AP. An attacker could exploit this vulnerability by sending authentication requests from multiple clients to an affected device. A successful exploit could allow the attacker to cause the affected device to reload.

Data is provided by the National Vulnerability Database (NVD)
CiscoWireless Lan Controller Version >= 8.9 < 8.10.112.0
   Cisco1111-4pwe Version-
   Cisco1111-8plteeawb Version-
   Cisco1111-8pwb Version-
   Cisco1113-8plteeawe Version-
   Cisco1113-8pmwe Version-
   Cisco1113-8pwe Version-
   Cisco1116-4plteeawe Version-
   Cisco1116-4pwe Version-
   Cisco1117-4plteeawe Version-
   Cisco1117-4pmlteeawe Version-
   Cisco1117-4pmwe Version-
   Cisco1117-4pwe Version-
   CiscoAironet 1815 Version-
   CiscoAironet 1830e Version-
   CiscoAironet 1830i Version-
   CiscoAironet 1850e Version-
   CiscoAironet 1850i Version-
   CiscoBusiness 140ac Version-
   CiscoBusiness 145ac Version-
   CiscoBusiness 240ac Version-
CiscoBusiness Access Points Version >= 10.0 < 10.1.1.0
CiscoAccess Points Version < 16.12.4a
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst 9800-l-c Version-
   CiscoCatalyst 9800-l-f Version-
CiscoAironet Access Point Software Version8.5(151.0)
   CiscoAironet 1850e Version-
   CiscoAironet 1850i Version-
CiscoAironet Access Point Software Version17.2.0.26
   CiscoAironet 1850e Version-
   CiscoAironet 1850i Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.28% 0.777
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
psirt@cisco.com 6.8 2.2 4
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.