Cisco IOS XE Wireless Controller Software Cisco Discovery Protocol Denial of Service Vulnerability
TL;DR 📌
A high-severity vulnerability has been identified in Cisco IOS XE Wireless Controller Software, allowing unauthenticated adjacent attackers to cause a denial of service (DoS) condition. Cisco has released software updates to address this issue, and there are no workarounds available.
What happened 🕵️♂️
A vulnerability in the Cisco IOS XE Wireless Controller Software could enable an unauthenticated, adjacent attacker to exploit insufficient input validation of Cisco Discovery Protocol (CDP) neighbor reports. By sending a crafted CDP packet to an affected access point (AP), an attacker could trigger an unexpected reload of the wireless controller managing the AP, resulting in a DoS condition that disrupts the wireless network.
Affected products 🖥️
The following Cisco products are affected if they are running a vulnerable release of Cisco IOS XE Software and have AP CDP enabled:
- Catalyst 9800-CL Wireless Controllers for Cloud
- Catalyst 9800 Embedded Wireless Controllers for Catalyst 9300, 9400, and 9500 Series Switches
- Catalyst 9800 Series Wireless Controllers
- Embedded Wireless Controllers on Catalyst APs
To determine if a device is affected, check if CDP is enabled for any APs managed by the device.
Fixed software 🔧
Upgrade to at least the first fixed release in your train (or later):
| Product / Release Train | First Fixed Release | Notes |
|---|---|---|
| ISE / ISE-PIC 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds that directly address this vulnerability. However, if CDP is not required on the AP, administrators can disable CDP on every AP profile through the web-based management GUI or CLI.
Risk in context 🎯
With a CVSS score of 7.4, this vulnerability is classified as high severity. Organizations using affected Cisco products should prioritize applying the necessary software updates to mitigate the risk of a denial of service attack that could disrupt wireless network operations.
Fast facts ⚡
- Advisory ID: cisco-sa-ewlc-cdp-dos-fpeks9K
- CVSS Score: 7.4 (HIGH)
- Vulnerability Type: Denial of Service (DoS)
- Exploitation: Unauthenticated, adjacent attacker
- Impact: Unexpected reload of wireless controller
For leadership 🧭
Executive summary. Any attacker within radio or physical reach of an access point on affected Cisco IOS XE Wireless Controller platforms can force the controller to reload, taking down wireless service across every AP it manages, with no authentication required. There is no workaround beyond disabling CDP, so this needs scheduling into the next change window rather than left for routine patch cycles.
Why it matters:
- The flaw sits in CDP neighbor-report handling on the wireless controller, so a single crafted packet reaching an AP can reload the controller and drop every AP and client it serves, not just the targeted device.
- No authentication is needed and the attacker only needs adjacency to an AP, which in wireless deployments can mean anyone within radio range of the site, not someone already on the network.
- Affected platforms include Catalyst 9800 Series and 9800-CL controllers, embedded controllers on Catalyst 9300/9400/9500 switches, and embedded controllers on Catalyst APs, so exposure spans both dedicated appliance and embedded deployment models.
- Cisco has published no workaround that fixes the vulnerability itself; the only mitigation is disabling CDP on AP profiles, which removes a feature some sites rely on for neighbour discovery.
Now / Next / Later:
- Now: Check every AP profile on Catalyst 9800 controllers, embedded 9800 controllers on 9300/9400/9500 switches, and embedded controllers on Catalyst APs to see whether CDP is enabled, and disable it via GUI or CLI on any AP where it is not actively needed.
- Next: Upgrade affected controllers to a fixed IOS XE release in your train during the next maintenance window, since disabling CDP is a stopgap and not a fix.
- Later: Review whether CDP needs to be enabled by default on AP profiles across the wireless estate, and build controller software currency for CDP-related and similar input-handling advisories into routine patch planning.