Incomplete cleanup in Cisco Systems, Inc products - CVE-2024-20303
Published: March 28, 2024 / Updated: March 29, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incomplete cleanup in the multicast DNS (mDNS) gateway feature. A remote attacker on the local network can cause the wireless controller to have high CPU utilization, leading to denial of service condition.
Affected software
Catalyst 9800 Embedded Wireless Controller
Catalyst 9800 Series Wireless Controllers
Embedded Wireless Controller on Catalyst Access Points
Cisco IOS XE