CVE-2023-20056

Severity
5.5MEDIUM
EPSS
0.3%
top 44.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23

Description

A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to cause an affected device to reload spontan

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 2.0 | Impact: 4.0

Affected Packages4 packages

🔴Vulnerability Details

2
CVEList
Cisco Access Point Software Denial of Service Vulnerability2023-03-23
GHSA
GHSA-qf58-8wfv-957j: A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (D2023-03-23

📋Vendor Advisories

1
Cisco
Cisco Access Point Software Denial of Service Vulnerability2023-03-22
CVE-2023-20056 (MEDIUM CVSS 5.5) | A vulnerability in the management C | cvebase.io