Input validation error in Cisco Systems, Inc products - CVE-2023-20112
Published: March 23, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of certain parameters within 802.11 frames in Cisco access point (AP) software. A remote attacker on the local network can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
Catalyst 9800 Wireless Controller Software
Catalyst 9100 Access Points
Cisco Business 151 Mesh Extender
Wireless LAN Controller Software
How to mitigate CVE-2023-20112
Catalyst 9800 Wireless Controller Software - addressed in versions 16.12.8, 17.3.5, 17.6.3
Cisco Business 151 Mesh Extender - update to 10.3.2.0
Wireless LAN Controller Software - update to 8.10.171.0