PT-2022-7008 · Cisco · Catalyst 9124+5
Published
2022-10-27
·
Updated
2024-01-25
·
CVE-2023-20176
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco access point (AP) software (affected versions not specified)
Cisco Catalyst 9124, Catalyst 9130, Catalyst 9136, Catalyst 9164, and Catalyst 9166 (affected versions not specified)
Description
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as a wireless client and sending a high rate of traffic over an extended period of time. A successful exploit could allow the attacker to cause the Datagram TLS (DTLS) session to tear down and reset, causing a denial of service (DoS) condition.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Catalyst 9124
Catalyst 9130
Catalyst 9136
Catalyst 9164
Catalyst 9166
Cisco Access Point