CVE-2023-20176
published 2023-09-27CVE-2023-20176: A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption…
PriorityP347high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
0.65%
47.0th percentile
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service.
This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as a wireless client and sending a high rate of traffic over an extended period of time. A successful exploit could allow the attacker to cause the Datagram TLS (DTLS) session to tear down and reset, causing a denial of service (DoS) condition.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst_9100_access_points | — | — |
| cisco | catalyst_9124_firmware | < 17.6.6 | 17.6.6 |
| cisco | catalyst_9130_firmware | < 17.6.6 | 17.6.6 |
| cisco | catalyst_9136_firmware | < 17.6.6 | 17.6.6 |
| cisco | catalyst_9164_firmware | < 17.6.6 | 17.6.6 |
| cisco | catalyst_9166_firmware | < 17.6.6 | 17.6.6 |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | cisco_aironet_access_point_software | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Catalyst 9100 Access Points Denial of Service Vulnerability
vendor_cisco·2023-09-27·CVSS 5.8
CVE-2023-20176 [MEDIUM] CWE-400 Cisco Catalyst 9100 Access Points Denial of Service Vulnerability
Cisco Catalyst 9100 Access Points Denial of Service Vulnerability
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service.
This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as a wireless client and sending a high rate of traffic over an extended period of time. A successful exploit could allow the attacker to cause the Datagram TLS (DTLS) session to tear down and reset, causing a denial of service (DoS) condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following
Cisco
Cisco Catalyst 9100 Access Points Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2023-20176 Cisco Catalyst 9100 Access Points Denial of Service Vulnerability
CVE-2023-20176: Cisco Catalyst 9100 Access Points Denial of Service Vulnerability
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as a wireless client and sending a high rate of traffic over an extended period of time. A successful exploit could allow the attacker to cause the Datagram TLS (DTLS) session to tear down and reset, causing a denial of service (DoS) condition. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-400, CWE-400
Bug IDs: CSCwb56120
GHSA
GHSA-68hh-p8m2-hpx3: A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary d
ghsa_unreviewed·2023-09-27
CVE-2023-20176 [HIGH] CWE-400 GHSA-68hh-p8m2-hpx3: A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary d
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service.
This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as a wireless client and sending a high rate of traffic over an extended period of time. A successful exploit could allow the attacker to cause the Datagram TLS (DTLS) session to tear down and reset, causing a denial of service (DoS) condition.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-09-27
Published