CVE Database
/

CVE-2023-20176

Back to search

CVE-2023-20176

Published: Sep 27, 2023

Modified: Aug 2, 2024

PUBLISHED

CVSS v3.1

5.8

MEDIUM

Description

A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as a wireless client and sending a high rate of traffic over an extended period of time. A successful exploit could allow the attacker to cause the Datagram TLS (DTLS) session to tear down and reset, causing a denial of service (DoS) condition.

VendorProductVersions

Cisco

Cisco Aironet Access Point Software

affected
8.10.170.0

Cisco

Cisco Aironet Access Point Software (IOS XE Controller)

affected
16.10.1e
affected
16.10.1
affected
17.1.1t
affected
17.1.1s
affected
17.1.1

+37 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

None

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now