CVE-2024-20271 Details
Description
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this vulnerability by sending a crafted IPv4 packet either to or through an affected device. A successful exploit could allow the attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To successfully exploit this vulnerability, the attacker does not need to be associated with the affected AP. This vulnerability cannot be exploited by sending IPv6 packets.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 28, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco ios xe | < 17.3.8 >= 17.4, < 17.6.6 >= 17.7, < 17.9.5 >= 17.10, < 17.12.2 |
CPE
Remediation
| |
| cisco business access points | < 10.9.1.0 < 10.6.2.0 |
CPE
Remediation
| |
| cisco business 140ac | All versions |
CPE
Remediation
| |
| cisco business 140ac access point | All versions |
CPE
Remediation
| |
| cisco business 141acm | All versions |
CPE
Remediation
| |
| cisco business 142acm | All versions |
CPE
Remediation
| |
| cisco business 143acm | All versions |
CPE
Remediation
| |
| cisco business 145ac | All versions |
CPE
Remediation
| |
| cisco business 145ac access point | All versions |
CPE
Remediation
| |
| cisco business 240ac | All versions |
CPE
Remediation
| |
| cisco business 150ax | All versions |
CPE
Remediation
| |
| cisco business 150ax access point | All versions |
CPE
Remediation
| |
| cisco business 151axm | All versions |
CPE
Remediation
| |
| cisco wireless lan controller software | < 8.10.190.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2025 | Initial Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Mar 27, 2024 | New CVE Received | [email protected] |