VendorsCiscocatalyst_9117all versions
Vulnerabilities

Cisco Catalyst 9117

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2020-3560
Cisco Aironet Access Points UDP Flooding Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.014
CVE-2021-1615
Cisco Embedded Wireless Controller Software for Catalyst Access Points Denial of Service Vulnerability
Published 2021-09-23 · Modified
8.6EPSS 0.013
CVE-2022-20919
Cisco IOS and IOS XE Software Common Industrial Protocol Request Denial of Service Vulnerability
Published 2022-09-30 · Modified
8.6EPSS 0.011
CVE-2024-20259
A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a crafted IPv4 DHCP request packet being mishandled when endpoint analytics are enabled. An attacker could exploit this vulnerability by sending a crafted DHCP request through an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Note: The attack vector is listed as network because a DHCP relay anywhere on the network could allow exploits from networks other than the adjacent one.
Published 2024-03-27 · Analyzed
8.6EPSS 0.008
CVE-2022-20855
Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst Access Points Privilege Escalation Vulnerability
Published 2022-09-30 · Modified
7.9EPSS 0.004
CVE-2020-3486
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerabilities
Published 2020-09-24 · Modified
7.4EPSS 0.006
CVE-2021-34740
Cisco Aironet Access Points WLAN Control Protocol Packet Buffer Leak Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2023-20112
Cisco Access Point Software Association Request Denial of Service Vulnerability
Published 2023-03-23 · Modified
7.4EPSS 0.003
CVE-2023-20097
Cisco Access Point Software Command Injection Vulnerability
Published 2023-03-23 · Modified
6.7EPSS 0.002
CVE-2020-26140
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.
Published 2021-05-11 · Modified
6.5EPSS 0.029
CVE-2023-20056
Cisco Access Point Software Denial of Service Vulnerability
Published 2023-03-23 · Modified
6.5EPSS 0.003
CVE-2020-26139
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.
Published 2021-05-11 · Modified
5.3EPSS 0.065
CVE-2025-20196
A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to stop responding, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to cause the Cisco IOx application hosting environment to stop responding. The IOx process will need to be manually restarted to recover services.
Published 2025-05-07 · Analyzed
5.3EPSS 0.004
CVE-2020-24588
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary network packets.
Published 2021-05-11 · Modified
3.5EPSS 0.036
CVE-2020-24587
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.
Published 2021-05-11 · Modified
2.6EPSS 0.026