Input validation error in Cisco Systems, Inc products - CVE-2023-20112

 

Input validation error in Cisco Systems, Inc products - CVE-2023-20112

Published: March 23, 2023


Vulnerability identifier: #VU73968
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20112
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of certain parameters within 802.11 frames in Cisco access point (AP) software. A remote attacker on the local network can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Cisco Business 150 AP
Catalyst 9800 Wireless Controller Software
Catalyst 9100 Access Points
Cisco Business 151 Mesh Extender
Wireless LAN Controller Software

How to mitigate CVE-2023-20112

Install updates from vendor's website.

Cisco Business 150 AP - update to 10.3.2.0
Catalyst 9800 Wireless Controller Software - addressed in versions 16.12.8, 17.3.5, 17.6.3
Cisco Business 151 Mesh Extender - update to 10.3.2.0
Wireless LAN Controller Software - update to 8.10.171.0

External References

Related Security Bulletins