Resource exhaustion in Catalyst 9100 Access Points and Catalyst 9800 Wireless Controller Software - CVE-2023-20176

 

Resource exhaustion in Catalyst 9100 Access Points and Catalyst 9800 Wireless Controller Software - CVE-2023-20176

Published: September 28, 2023


Vulnerability identifier: #VU81258
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-20176
CWE-ID: CWE-400
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Catalyst 9100 Access Points
Catalyst 9800 Wireless Controller Software
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper control over consumption of internal resources. A remote attacker can connect to the affected AP as a client and send a high rate of traffic over an extended period of time, which will result in an overuse of AP resources and denial of service.


Remediation

Install updates from vendor's website.

External links