// For flags

CVE-2024-20336

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

A vulnerability in the web-based user interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to perform buffer overflow attacks against an affected device. In order to exploit this vulnerability, the attacker must have valid administrative credentials for the device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system.

Una vulnerabilidad en la interfaz de usuario basada en web de los AP inalámbricos Cisco Small Business series 100, 300 y 500 podría permitir que un atacante remoto autenticado realice ataques de desbordamiento de búfer contra un dispositivo afectado. Para aprovechar esta vulnerabilidad, el atacante debe tener credenciales administrativas válidas para el dispositivo. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario. Un atacante podría aprovechar esta vulnerabilidad enviando una solicitud HTTP manipulada a la interfaz de administración basada en web de un dispositivo afectado. Un exploit exitoso podría permitir al atacante ejecutar código arbitrario como usuario root en el sistema operativo subyacente.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2023-11-08 CVE Reserved
  • 2024-03-06 CVE Published
  • 2024-03-07 EPSS Updated
  • 2024-08-01 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-121: Stack-based Buffer Overflow
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Cisco Business Wireless Access Point Software
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software"
1.0.0.3
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software" and version "1.0.0.3"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Business Wireless Access Point Software
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software"
1.0.0.4
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software" and version "1.0.0.4"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Business Wireless Access Point Software
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software"
1.0.0.5
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software" and version "1.0.0.5"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Business Wireless Access Point Software
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software"
1.0.0.7
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software" and version "1.0.0.7"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Business Wireless Access Point Software
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software"
1.0.1.3
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software" and version "1.0.1.3"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Business Wireless Access Point Software
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software"
1.0.1.5
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software" and version "1.0.1.5"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Business Wireless Access Point Software
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software"
1.0.1.7
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software" and version "1.0.1.7"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Business Wireless Access Point Software
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software"
1.0.2.0
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software" and version "1.0.2.0"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Business Wireless Access Point Software
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software"
1.0.3.1
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software" and version "1.0.3.1"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Business Wireless Access Point Software
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software"
1.0.4.4
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software" and version "1.0.4.4"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Business Wireless Access Point Software
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software"
1.0.4.3
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software" and version "1.0.4.3"
en
Affected
Cisco
Search vendor "Cisco"
Cisco Business Wireless Access Point Software
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software"
1.0.5.0
Search vendor "Cisco" for product "Cisco Business Wireless Access Point Software" and version "1.0.5.0"
en
Affected