Cisco IOS XE Unauthenticated Access to PKI Server Vulnerability in Catalyst 9800-CL Controllers

Vulnerability

A vulnerability exists in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL). This vulnerability allows an unauthenticated, remote attacker to access the public-key infrastructure (PKI) server on the affected device. The issue arises from incomplete cleanup after the Day One setup, enabling attackers to send Simple Certificate Enrollment Protocol (SCEP) requests, request certificates from the virtual wireless controller, and use those certificates to join attacker-controlled devices to the controller.

Impact

Exploitation of this vulnerability could lead to unauthorized access to the PKI server, allowing attackers to enroll certificates and potentially join malicious devices to the virtual wireless controller.

Remediation

Administrators can shut down the PKI server associated with the wireless LAN controller hostname to mitigate this vulnerability. Cisco has also released software updates to address the issue.

Added: Sep 24, 2025, 6:56 PM
Updated: Sep 24, 2025, 6:56 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
1.3
exploitability
7.0
remediation
8.3
relevance
0.6
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.