Resource exhaustion in Catalyst 9100 Access Points and Catalyst 9800 Wireless Controller Software - CVE-2023-20176

 

Resource exhaustion in Catalyst 9100 Access Points and Catalyst 9800 Wireless Controller Software - CVE-2023-20176

Published: September 28, 2023


Vulnerability identifier: #VU81258
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20176
CWE-ID: CWE-400
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper control over consumption of internal resources. A remote attacker can connect to the affected AP as a client and send a high rate of traffic over an extended period of time, which will result in an overuse of AP resources and denial of service.


Affected software

Catalyst 9100 Access Points
Catalyst 9800 Wireless Controller Software

How to mitigate CVE-2023-20176

Install updates from vendor's website.

Catalyst 9800 Wireless Controller Software - update to 17.6.6

External References

Related Security Bulletins