VDB
CVE-2020-3552
CVE-2020-3552
PUBLISHED
CVSS 7.400000095367432 HIGH
A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by connecting as a wired client to the Ethernet interface of an affected device and sending a series of specific packets within a short time frame. A successful exploit could allow the attacker to cause a NULL pointer access that results in a reload of the affected device.
EPSS 0.10% · 27.5th percentile
Risk Scores
CVSS 3.0
7.400000095367432
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS Score
0.10%
27.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | aironet_access_point_software | 8.10\(1.255\) |
| cisco | access_points | 0 |
| cisco | business_access_points | 10.0 |
| Cisco | Cisco Aironet Access Point Software | n/a |
| cisco | wireless_lan_controller | 8.6 |
Exploit Intelligence
Timeline
- Sep 24, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score