Resource exhaustion in Cisco Systems, Inc products - CVE-2023-20268
Published: September 28, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper control over consumption of internal resources when handling certain types of traffic. A remote attacker on the local network can send specially crafted traffic to the device, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Cisco Business 150 Series AP Software
Catalyst 9800 Wireless Controller Software
How to mitigate CVE-2023-20268
Cisco Business 150 Series AP Software - update to 10.6.2.0
Catalyst 9800 Wireless Controller Software - addressed in versions 17.3.8, 17.6.6, 17.9.4