CVE-2024-20303 — Incomplete Cleanup in Cisco IOS XE Software
Severity
7.4HIGHNVD
EPSS
0.1%
top 81.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 27
Description
A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.
This vulnerability is due to improper management of mDNS client entries. An attacker could exploit this vulnerability by connecting to the wireless network and sending a continuous stream of specific mDNS packets. A successful exploit could allow the attacker to cause the wireless c…
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 2.8 | Impact: 4.0
Affected Packages2 packages
🔴Vulnerability Details
2CVEList▶
CVE-2024-20303: A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticate↗2024-03-27
GHSA▶
GHSA-jfv4-r4r3-xx7w: A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticate↗2024-03-27
📋Vendor Advisories
1Cisco▶
Cisco IOS XE Software for Wireless LAN Controllers Multicast DNS Denial of Service Vulnerability↗2024-03-27