PT-2022-7008 · Cisco · Catalyst 9124+5

Published

2022-10-27

·

Updated

2024-01-25

·

CVE-2023-20176

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco access point (AP) software (affected versions not specified) Cisco Catalyst 9124, Catalyst 9130, Catalyst 9136, Catalyst 9164, and Catalyst 9166 (affected versions not specified)
Description A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as a wireless client and sending a high rate of traffic over an extended period of time. A successful exploit could allow the attacker to cause the Datagram TLS (DTLS) session to tear down and reset, causing a denial of service (DoS) condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2023-06361
CVE-2023-20176

Affected Products

Catalyst 9124
Catalyst 9130
Catalyst 9136
Catalyst 9164
Catalyst 9166
Cisco Access Point