Catalyst 9800 40 Wireless Controller
Vendor:
First CVE: Sep 29, 2017 · Active for 8 years
12
Total CVEs
More Total CVEs than 90% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
16.7%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Catalyst 9800 40 Wireless Controller over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 29, 2017
8 years ago
Most Recent CVE
Mar 23, 2023
1,219 days ago
CVE Severity & Scoring
Catalyst 9800 40 Wireless Controller12 CVEs
42%
50%
8%
All CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (16.7%)
Network10 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (83.3%)
High2 (16.7%)
Unknown0 (0.0%)
User Interaction
None12 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (25.0%)
High1 (8.3%)
None8 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0154HIGH A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a | Mar 28, 2018 | 7.5 | 66 | YES | NO |
CVE-2017-12231HIGH A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a d | Sep 29, 2017 | 7.5 | 65 | YES | NO |
CVE-2021-34770CRITICAL A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers | Sep 23, 2021 | 9.8 | 32 | NO | NO |
CVE-2022-20919HIGH A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated | Sep 30, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-20065HIGH A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected de | Mar 23, 2023 | 7.8 | 24 | NO | NO |
CVE-2021-34769HIGH Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Con | Sep 23, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-34768HIGH Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Con | Sep 23, 2021 | 7.5 | 24 | NO | NO |
CVE-2019-1649MEDIUM A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local att | May 13, 2019 | 6.7 | 24 | NO | NO |
CVE-2023-20100MEDIUM A vulnerability in the access point (AP) joining process of the Control and Provisioning of Wireless Access Points (CAPWAP) protocol of Cisco IOS XE Software for Wireless LAN Contr | Mar 23, 2023 | 6.8 | 23 | NO | NO |
CVE-2023-20081MEDIUM A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and | Mar 23, 2023 | 5.9 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
2 CVEs
16.7% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Catalyst 9800 40 Wireless Controller
Top CWEs
Versions
No cataloged versions.