cbcvebase.
CVE-2020-3418
published 2020-09-24

CVE-2020-3418: A vulnerability in Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9800 Series Routers could allow an unauthenticated, adjacent attacker to send…

PriorityP421medium4.7CVSS 3.1
AVAACLPRNUINSCCNILAN
EPSS
0.41%
33.8th percentile
A vulnerability in Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9800 Series Routers could allow an unauthenticated, adjacent attacker to send ICMPv6 traffic prior to the client being placed into RUN state. The vulnerability is due to an incomplete access control list (ACL) being applied prior to RUN state. An attacker could exploit this vulnerability by connecting to the associated service set identifier (SSID) and sending ICMPv6 traffic. A successful exploit could allow the attacker to send ICMPv6 traffic prior to RUN state.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscocisco_ios_xe_software
ciscoios_xe
ciscoios_xe_wireless_controller
msrccbl2_grub2_2.06rc1-7_on_cbl_mariner_2.0

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv3.04.7MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:P/A:N
vendor_msrc6.4MEDIUM
vendor_redhat6.4MEDIUM
vendor_cisco4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.