aironet_access_point_software_ios_xe_controller vulnerabilities
CVEs whose affected-version data names the aironet_access_point_software_ios_xe_controller package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
15 CVEsRSS
CVE-2025-20365Medium· 4.3Cisco Access Point Software Intermittent IPv6 Gateway Change Vulnerability (CVE-2025-20365)
A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway on an affected device. This vulnerability is due to a lo…
CVE-2025-20364Medium· 4.3Cisco Wireless Access Point Software Device Analytics Action Frame Injection Vulnerability (CVE-2025-20364)
A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vuln…
CVE-2024-20271High· 8.6Cisco Access Point Software Denial of Service Vulnerability (CVE-2024-20271)
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficien…
CVE-2024-20265Medium· 5.9Cisco Access Point Software Secure Boot Bypass Vulnerability (CVE-2024-20265)
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisco Secure Boot functionality and load a software image that has been tampered with on an affected de…
CVE-2023-20268Medium· 4.7Cisco Access Point Software Uncontrolled Resource Consumption Vulnerability (CVE-2023-20268)
A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device. This vulnerability is due to insufficient managemen…
CVE-2023-20176Medium· 5.8Cisco Aironet Access Points Denial of Service
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacke…
CVE-2023-20056Medium· 6.5Cisco Access Point Software Denial of Service
A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input v…
CVE-2023-20112High· 7.4Cisco Access Point Software Association Request Denial of Service Vulnerability (CVE-2023-20112)
A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain pa…
CVE-2023-20097Medium· 4.6Cisco Access Points (AP) Command Injection Vulnerability
A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands tha…
CVE-2022-20728Medium· 4.7Cisco Aironet Access Points VLAN bypass from Native VLAN Vulnerability
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This v…
CVE-2022-20622High· 8.6Cisco Aironet Access Points ICMP Denial of Service Vulnerability
A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of …
CVE-2021-34740High· 7.4Cisco Aironet Access Points WLAN Control Protocol Packet Buffer Leak Denial of Service Vulnerability (CVE-2021-34740)
A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS…
CVE-2021-1419High· 7.8Cisco Aironet Access Points Privilege Escalation Vulnerability
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is du…
CVE-2021-1449Medium· 6.7Cisco Aironet Access Points Privilege Escalation Vulnerability
A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code th…
CVE-2021-1437High· 7.5Cisco Aironet Access Points FlexConnect Upgrade Information Disclosure Vulnerability (CVE-2021-1437)
A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to a…