VulnSea

aironet_access_point_software_ios_xe_controller vulnerabilities

CVEs whose affected-version data names the aironet_access_point_software_ios_xe_controller package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

15 CVEsRSS

CVE-2025-20365Medium· 4.3
12mo ago

Cisco Access Point Software Intermittent IPv6 Gateway Change Vulnerability (CVE-2025-20365)

A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway on an affected device. This vulnerability is due to a lo…

SunlitCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 0.17%via CSAF
CVE-2025-20364Medium· 4.3
12mo ago

Cisco Wireless Access Point Software Device Analytics Action Frame Injection Vulnerability (CVE-2025-20364)

A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vuln…

SunlitCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 0.12%via CSAF
CVE-2024-20271High· 8.6
2y ago

Cisco Access Point Software Denial of Service Vulnerability (CVE-2024-20271)

A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficien…

TwilightCisco · Cisco Aironet Access Point SoftwareEPSS 0.63%via CSAF
CVE-2024-20265Medium· 5.9
2y ago

Cisco Access Point Software Secure Boot Bypass Vulnerability (CVE-2024-20265)

A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisco Secure Boot functionality and load a software image that has been tampered with on an affected de…

SunlitCisco · Cisco IOS XE SoftwareEPSS 0.25%via CSAF
CVE-2023-20268Medium· 4.7
2y ago

Cisco Access Point Software Uncontrolled Resource Consumption Vulnerability (CVE-2023-20268)

A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device. This vulnerability is due to insufficient managemen…

SunlitCisco · Cisco Business Wireless Access Point SoftwareEPSS 0.24%via CSAF
CVE-2023-20176Medium· 5.8
2y ago

Cisco Aironet Access Points Denial of Service

A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacke…

SunlitCisco · Cisco Aironet Access Point SoftwareEPSS 0.65%via CSAF
CVE-2023-20056Medium· 6.5
3y ago

Cisco Access Point Software Denial of Service

A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input v…

SunlitCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 0.26%via CSAF
CVE-2023-20112High· 7.4
3y ago

Cisco Access Point Software Association Request Denial of Service Vulnerability (CVE-2023-20112)

A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain pa…

TwilightCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 0.30%via CSAF
CVE-2023-20097Medium· 4.6
3y ago

Cisco Access Points (AP) Command Injection Vulnerability

A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands tha…

SunlitCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 0.24%via CSAF
CVE-2022-20728Medium· 4.7
3y ago

Cisco Aironet Access Points VLAN bypass from Native VLAN Vulnerability

A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This v…

SunlitCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 0.26%via CSAF
CVE-2022-20622High· 8.6
4y ago

Cisco Aironet Access Points ICMP Denial of Service Vulnerability

A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of …

TwilightCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 1.4%via CSAF
CVE-2021-34740High· 7.4
5y ago

Cisco Aironet Access Points WLAN Control Protocol Packet Buffer Leak Denial of Service Vulnerability (CVE-2021-34740)

A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS…

TwilightCisco · Cisco Aironet Access Point SoftwareEPSS 0.36%via CSAF
CVE-2021-1419High· 7.8
5y ago

Cisco Aironet Access Points Privilege Escalation Vulnerability

A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is du…

TwilightCisco · Cisco 5500 Series Wireless ControllersEPSS 0.22%via CSAF
CVE-2021-1449Medium· 6.7
5y ago

Cisco Aironet Access Points Privilege Escalation Vulnerability

A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code th…

SunlitCisco · Cisco Aironet Access Point SoftwareEPSS 0.27%via CSAF
CVE-2021-1437High· 7.5
5y ago

Cisco Aironet Access Points FlexConnect Upgrade Information Disclosure Vulnerability (CVE-2021-1437)

A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to a…

TwilightCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 1.5%via CSAF
aironet_access_point_software_ios_xe_controller vulnerabilities (CVEs) · VulnSea