CVE-2020-3273 describes a denial-of-service vulnerability in Cisco Wireless LAN Controller (WLC) Software, specifically affecting the 5508 and 5520 series. This flaw stems from incomplete input validation of 802.11 Generic Advertisement Service (GAS) frames. An unauthenticated, remote attacker can exploit this by sending a crafted GAS frame, either over the air via an access point or directly to the WLC via a CAPWAP packet, causing the device to reload. The vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and no user interaction required, leading to a complete loss of availability. Despite its high severity, the EPSS score is very low, suggesting a minimal likelihood of exploitation. Currently, there is no known active exploitation, nor are there public exploit codes available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are also minimal, indicating a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.5\(151.0\)CPE matchmatch criteria | cpe:2.3:o:cisco:5508_wireless_controller_firmware:8.5\(151.0\):*:*:*:*:*:*:* | ||
8.10\(204.92\)CPE matchmatch criteria | cpe:2.3:o:cisco:5508_wireless_controller_firmware:8.10\(204.92\):*:*:*:*:*:*:* | ||
8.5\(151.0\)CPE matchmatch criteria | cpe:2.3:o:cisco:5520_wireless_controller_firmware:8.5\(151.0\):*:*:*:*:*:*:* | ||
8.10\(204.92\)CPE matchmatch criteria | cpe:2.3:o:cisco:5520_wireless_controller_firmware:8.10\(204.92\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.