NA

CVE-2023-20202

Published: 27/09/2023 Updated: 25/01/2024
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent malicious user to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network requests to an affected device. A successful exploit could allow the malicious user to cause the wncd process to consume available memory and eventually cause the device to reload, resulting in a DoS condition.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xe 17.9.1

cisco ios xe 17.9.1a

cisco ios xe 17.9.1w

cisco ios xe 17.9.1x

cisco ios xe 17.9.1x1

cisco ios xe 17.9.1y

cisco ios xe 17.9.2

cisco ios xe 17.9.2a

cisco ios xe 17.9.2b

cisco ios xe 17.10.1

cisco ios xe 17.10.1a

cisco ios xe 17.10.1b

Vendor Advisories

A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition This vulnerability is due to improper memory management An attacker could exploit this vulnerability by sending a series of network reque ...