CVE-2025-20140
Description
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of IPv6 network requests from an associated wireless IPv6 client to an affected device. To associate a client to a device, an attacker may first need to authenticate to the network, or associate freely in the case of a configured open network. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to stop responding, resulting in a DoS condition.
CVSS Details
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Threat Intelligence
Weaknesses 1
Affected Products 210
| Vendor | Product | Version | Range |
|---|---|---|---|
| cisco | ios_xe | 16.4.1 | any |
| cisco | ios_xe | 16.4.2 | any |
| cisco | ios_xe | 16.4.3 | any |
| cisco | ios_xe | 16.5.1 | any |
| cisco | ios_xe | 16.5.1a | any |
| cisco | ios_xe | 16.5.1b | any |
| cisco | ios_xe | 16.5.2 | any |
| cisco | ios_xe | 16.5.3 | any |
| cisco | ios_xe | 16.6.1 | any |
| cisco | ios_xe | 16.6.2 | any |
| cisco | ios_xe | 16.6.3 | any |
| cisco | ios_xe | 16.6.4 | any |
| cisco | ios_xe | 16.6.4a | any |
| cisco | ios_xe | 16.6.5 | any |
| cisco | ios_xe | 16.6.5a | any |
| cisco | ios_xe | 16.6.6 | any |
| cisco | ios_xe | 16.6.7 | any |
| cisco | ios_xe | 16.6.8 | any |
| cisco | ios_xe | 16.6.9 | any |
| cisco | ios_xe | 16.6.10 | any |
| cisco | ios_xe | 16.7.1 | any |
| cisco | ios_xe | 16.7.1a | any |
| cisco | ios_xe | 16.7.1b | any |
| cisco | ios_xe | 16.7.2 | any |
| cisco | ios_xe | 16.7.3 | any |
| cisco | ios_xe | 16.7.4 | any |
| cisco | ios_xe | 16.8.1 | any |
| cisco | ios_xe | 16.8.1a | any |
| cisco | ios_xe | 16.8.1b | any |
| cisco | ios_xe | 16.8.1c | any |
| cisco | ios_xe | 16.8.1d | any |
| cisco | ios_xe | 16.8.1e | any |
| cisco | ios_xe | 16.8.1s | any |
| cisco | ios_xe | 16.8.2 | any |
| cisco | ios_xe | 16.8.3 | any |
| cisco | ios_xe | 16.9.1 | any |
| cisco | ios_xe | 16.9.1a | any |
| cisco | ios_xe | 16.9.1b | any |
| cisco | ios_xe | 16.9.1s | any |
| cisco | ios_xe | 16.9.2 | any |
| cisco | ios_xe | 16.9.3 | any |
| cisco | ios_xe | 16.9.3a | any |
| cisco | ios_xe | 16.9.4 | any |
| cisco | ios_xe | 16.9.5 | any |
| cisco | ios_xe | 16.9.5f | any |
| cisco | ios_xe | 16.9.6 | any |
| cisco | ios_xe | 16.9.7 | any |
| cisco | ios_xe | 16.9.8 | any |
| cisco | ios_xe | 16.10.1 | any |
| cisco | ios_xe | 16.10.1a | any |
| cisco | ios_xe | 16.10.1b | any |
| cisco | ios_xe | 16.10.1c | any |
| cisco | ios_xe | 16.10.1d | any |
| cisco | ios_xe | 16.10.1e | any |
| cisco | ios_xe | 16.10.1f | any |
| cisco | ios_xe | 16.10.1g | any |
| cisco | ios_xe | 16.10.1s | any |
| cisco | ios_xe | 16.10.2 | any |
| cisco | ios_xe | 16.10.3 | any |
| cisco | ios_xe | 16.11.1 | any |
| cisco | ios_xe | 16.11.1a | any |
| cisco | ios_xe | 16.11.1b | any |
| cisco | ios_xe | 16.11.1s | any |
| cisco | ios_xe | 16.11.2 | any |
| cisco | ios_xe | 16.12.1 | any |
| cisco | ios_xe | 16.12.1a | any |
| cisco | ios_xe | 16.12.1c | any |
| cisco | ios_xe | 16.12.1s | any |
| cisco | ios_xe | 16.12.1t | any |
| cisco | ios_xe | 16.12.1w | any |
| cisco | ios_xe | 16.12.1x | any |
| cisco | ios_xe | 16.12.1y | any |
| cisco | ios_xe | 16.12.1z1 | any |
| cisco | ios_xe | 16.12.1z2 | any |
| cisco | ios_xe | 16.12.2 | any |
| cisco | ios_xe | 16.12.2a | any |
| cisco | ios_xe | 16.12.2s | any |
| cisco | ios_xe | 16.12.3 | any |
| cisco | ios_xe | 16.12.3a | any |
| cisco | ios_xe | 16.12.3s | any |
| cisco | ios_xe | 16.12.4 | any |
| cisco | ios_xe | 16.12.4a | any |
| cisco | ios_xe | 16.12.5 | any |
| cisco | ios_xe | 16.12.5a | any |
| cisco | ios_xe | 16.12.5b | any |
| cisco | ios_xe | 16.12.6 | any |
| cisco | ios_xe | 16.12.6a | any |
| cisco | ios_xe | 16.12.7 | any |
| cisco | ios_xe | 16.12.8 | any |
| cisco | ios_xe | 16.12.9 | any |
| cisco | ios_xe | 16.12.10 | any |
| cisco | ios_xe | 16.12.10a | any |
| cisco | ios_xe | 16.12.11 | any |
| cisco | ios_xe | 16.12.12 | any |
| cisco | ios_xe | 17.1.1 | any |
| cisco | ios_xe | 17.1.1a | any |
| cisco | ios_xe | 17.1.1s | any |
| cisco | ios_xe | 17.1.1t | any |
| cisco | ios_xe | 17.1.3 | any |
| cisco | ios_xe | 17.2.1 | any |
| cisco | ios_xe | 17.2.1a | any |
| cisco | ios_xe | 17.2.1r | any |
| cisco | ios_xe | 17.2.1v | any |
| cisco | ios_xe | 17.2.2 | any |
| cisco | ios_xe | 17.2.3 | any |
| cisco | ios_xe | 17.3.1 | any |
| cisco | ios_xe | 17.3.1a | any |
| cisco | ios_xe | 17.3.1w | any |
| cisco | ios_xe | 17.3.1x | any |
| cisco | ios_xe | 17.3.1z | any |
| cisco | ios_xe | 17.3.2 | any |
| cisco | ios_xe | 17.3.2a | any |
| cisco | ios_xe | 17.3.3 | any |
| cisco | ios_xe | 17.3.4 | any |
| cisco | ios_xe | 17.3.4a | any |
| cisco | ios_xe | 17.3.4b | any |
| cisco | ios_xe | 17.3.4c | any |
| cisco | ios_xe | 17.3.5 | any |
| cisco | ios_xe | 17.3.5a | any |
| cisco | ios_xe | 17.3.5b | any |
| cisco | ios_xe | 17.3.6 | any |
| cisco | ios_xe | 17.3.7 | any |
| cisco | ios_xe | 17.3.8 | any |
| cisco | ios_xe | 17.3.8a | any |
| cisco | ios_xe | 17.4.1 | any |
| cisco | ios_xe | 17.4.1a | any |
| cisco | ios_xe | 17.4.1b | any |
| cisco | ios_xe | 17.4.2 | any |
| cisco | ios_xe | 17.4.2a | any |
| cisco | ios_xe | 17.5.1 | any |
| cisco | ios_xe | 17.5.1a | any |
| cisco | ios_xe | 17.6.1 | any |
| cisco | ios_xe | 17.6.1a | any |
| cisco | ios_xe | 17.6.1w | any |
| cisco | ios_xe | 17.6.1x | any |
| cisco | ios_xe | 17.6.1y | any |
| cisco | ios_xe | 17.6.1z | any |
| cisco | ios_xe | 17.6.1z1 | any |
| cisco | ios_xe | 17.6.2 | any |
| cisco | ios_xe | 17.6.3 | any |
| cisco | ios_xe | 17.6.3a | any |
| cisco | ios_xe | 17.6.4 | any |
| cisco | ios_xe | 17.6.5 | any |
| cisco | ios_xe | 17.6.5a | any |
| cisco | ios_xe | 17.6.6 | any |
| cisco | ios_xe | 17.6.6a | any |
| cisco | ios_xe | 17.6.7 | any |
| cisco | ios_xe | 17.6.8 | any |
| cisco | ios_xe | 17.6.8a | any |
| cisco | ios_xe | 17.7.1 | any |
| cisco | ios_xe | 17.7.1a | any |
| cisco | ios_xe | 17.7.1b | any |
| cisco | ios_xe | 17.7.2 | any |
| cisco | ios_xe | 17.8.1 | any |
| cisco | ios_xe | 17.8.1a | any |
| cisco | ios_xe | 17.9.1 | any |
| cisco | ios_xe | 17.9.1a | any |
| cisco | ios_xe | 17.9.1w | any |
| cisco | ios_xe | 17.9.1x | any |
| cisco | ios_xe | 17.9.1x1 | any |
| cisco | ios_xe | 17.9.1y | any |
| cisco | ios_xe | 17.9.1y1 | any |
| cisco | ios_xe | 17.9.2 | any |
| cisco | ios_xe | 17.9.2a | any |
| cisco | ios_xe | 17.9.3 | any |
| cisco | ios_xe | 17.9.3a | any |
| cisco | ios_xe | 17.9.4 | any |
| cisco | ios_xe | 17.9.4a | any |
| cisco | ios_xe | 17.9.5 | any |
| cisco | ios_xe | 17.9.5a | any |
| cisco | ios_xe | 17.9.5b | any |
| cisco | ios_xe | 17.9.5e | any |
| cisco | ios_xe | 17.9.5f | any |
| cisco | ios_xe | 17.10.1 | any |
| cisco | ios_xe | 17.10.1a | any |
| cisco | ios_xe | 17.10.1b | any |
| cisco | ios_xe | 17.11.1 | any |
| cisco | ios_xe | 17.11.1a | any |
| cisco | ios_xe | 17.11.99sw | any |
| cisco | ios_xe | 17.12.1 | any |
| cisco | ios_xe | 17.12.1a | any |
| cisco | ios_xe | 17.12.1w | any |
| cisco | ios_xe | 17.12.1x | any |
| cisco | ios_xe | 17.12.1y | any |
| cisco | ios_xe | 17.12.1z | any |
| cisco | ios_xe | 17.12.1z1 | any |
| cisco | ios_xe | 17.12.2 | any |
| cisco | ios_xe | 17.12.2a | any |
| cisco | ios_xe | 17.12.3 | any |
| cisco | ios_xe | 17.12.3a | any |
| cisco | ios_xe | 17.13.1 | any |
| cisco | ios_xe | 17.13.1a | any |
| cisco | ios_xe | 17.14.1 | any |
| cisco | ios_xe | 17.14.1a | any |
| cisco | catalyst_9800-cl_wireless_controllers_for_cloud | * | any |
| cisco | catalyst_9105axi | * | any |
| cisco | catalyst_9115axe | * | any |
| cisco | catalyst_9115axi | * | any |
| cisco | catalyst_9117axi | * | any |
| cisco | catalyst_9120axe | * | any |
| cisco | catalyst_9120axi | * | any |
| cisco | catalyst_9120axp | * | any |
| cisco | catalyst_9130axe | * | any |
| cisco | catalyst_9130axi | * | any |
| cisco | catalyst_9800-40 | * | any |
| cisco | catalyst_9800-80 | * | any |
| cisco | catalyst_9800-l | * | any |
| cisco | catalyst_cw9800h1 | * | any |
| cisco | catalyst_cw9800h2 | * | any |
| cisco | catalyst_cw9800m | * | any |
References 1
- sec.cloudapps.cisco.com https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-wncd-p6Gvt6HL
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.