Resource exhaustion in Cisco Systems, Inc products - CVE-2020-3559
Published: September 24, 2020 / Updated: September 29, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can send authentication requests, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Cisco Small Business 100 Series Wireless Access Points
Cisco Small Business 200 Series Smart Switches
Integrated Access Point on 1100 Integrated Services Routers
Cisco Catalyst 9800 Wireless Controller
Cisco Business Access Points
Cisco Wireless LAN Controller
How to mitigate CVE-2020-3559
Cisco Catalyst 9800 Wireless Controller - update to 16.12.4a
Cisco Business Access Points - update to 10.1.1.0