CVE-2023-20176 - CVE House
Back to Database
Status published Medium CVE-2023-20176

A vulnerability in the networking component of Cisco access point...

Vulnerability Description

A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as a wireless client and sending a high rate of traffic over an extended period of time. A successful exploit could allow the attacker to cause the Datagram TLS (DTLS) session to tear down and reset, causing a denial of service (DoS) condition.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-20176

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco Aironet Access Point Software, Cisco Aironet Access Point Software (IOS XE Controller)
Vulnerable Versions:
8.10.170.0, 16.10.1e, 16.10.1, 17.1.1t, 17.1.1s, 17.1.1, 16.11.1a, 16.11.1, 16.11.1c, 16.11.1b, 16.12.1s, 16.12.4, 16.12.1, 16.12.2s, 16.12.1t, 16.12.4a, 16.12.5, 16.12.3, 16.12.6, 16.12.8, 16.12.7, 16.12.6a, 17.3.1, 17.3.2a, 17.3.3, 17.3.2, 17.3.4c, 17.3.5a, 17.3.6, 17.2.1, 17.2.1a, 17.2.3, 17.2.2, 17.5.1, 17.4.1, 17.4.2, 17.6.1, 17.6.2, 17.6.3, 17.6.4, 17.6.5, 17.7.1, 17.8.1

Timeline

Official Publish: September 27th, 2023
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Weaknesses (CWE)