CVE-2025-20140

A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial

Severity
High 7.4
CVSS 3.1
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
0.002
14.8th percentile
Discovered by
Third party
Vendor-published field
Published
May 7, 2025
Assigned by cisco

Description

A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of IPv6 network requests from an associated wireless IPv6 client to an affected device. To associate a client to a device, an attacker may first need to authenticate to the network, or associate freely in the case of a configured open network. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to stop responding, resulting in a DoS condition.

Weakness: CWE-789

Affected products

Vendor Product Category Matched by
Cisco Cisco IOS XE Software Routing & Switching cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco IOS XE Software

Vendor advisory

cisco-sa-wlc-wncd-p6Gvt6HL

Cisco IOS XE Software for WLC Wireless IPv6 Clients Denial of Service Vulnerability

Cisco’s rating: High (advisory CVSS 7.4) · Published May 7, 2025

Bug ID: CSCwj16556

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?