Cisco IOS XE Wireless LAN Controllers Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs). This issue allows an unauthenticated, adjacent wireless attacker to disrupt service by sending a series of IPv6 network requests from an associated wireless IPv6 client to the affected device. The vulnerability arises from improper memory management, which can lead to the wncd process consuming excessive memory and causing the device to become unresponsive.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition, causing the affected device to stop responding to network requests.

Remediation

Cisco has released free software updates to address this vulnerability. Customers with service contracts should obtain these updates through their usual channels. For those without service contracts, contact the Cisco Technical Assistance Center (TAC) for assistance. Customers can also use the Cisco Software Checker tool to determine their exposure to this vulnerability and find the first fixed release.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
4.9
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.