// For flags

CVE-2023-20176

 

Severity Score

8.6
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service.
This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as a wireless client and sending a high rate of traffic over an extended period of time. A successful exploit could allow the attacker to cause the Datagram TLS (DTLS) session to tear down and reset, causing a denial of service (DoS) condition.

Una vulnerabilidad en el componente de red del software del punto de acceso (AP) de Cisco podría permitir que un atacante remoto no autenticado cause una interrupción temporal del servicio. Esta vulnerabilidad se debe al uso excesivo de los recursos AP. Un atacante podría aprovechar esta vulnerabilidad conectándose a un AP en un dispositivo afectado como cliente inalámbrico y enviando una alta tasa de tráfico durante un período prolongado de tiempo. Un exploit exitoso podría permitir al atacante provocar que la sesión de Datagram TLS (DTLS) se interrumpa y se reinicie, provocando una condición de denegación de servicio (DoS).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
Low
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-10-27 CVE Reserved
  • 2023-09-27 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-08-27 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-400: Uncontrolled Resource Consumption
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Catalyst 9166 Firmware
Search vendor "Cisco" for product "Catalyst 9166 Firmware"
< 17.6.6
Search vendor "Cisco" for product "Catalyst 9166 Firmware" and version " < 17.6.6"
-
Affected
in Cisco
Search vendor "Cisco"
Catalyst 9166
Search vendor "Cisco" for product "Catalyst 9166"
--
Safe
Cisco
Search vendor "Cisco"
Catalyst 9164 Firmware
Search vendor "Cisco" for product "Catalyst 9164 Firmware"
< 17.6.6
Search vendor "Cisco" for product "Catalyst 9164 Firmware" and version " < 17.6.6"
-
Affected
in Cisco
Search vendor "Cisco"
Catalyst 9164
Search vendor "Cisco" for product "Catalyst 9164"
--
Safe
Cisco
Search vendor "Cisco"
Catalyst 9136 Firmware
Search vendor "Cisco" for product "Catalyst 9136 Firmware"
< 17.6.6
Search vendor "Cisco" for product "Catalyst 9136 Firmware" and version " < 17.6.6"
-
Affected
in Cisco
Search vendor "Cisco"
Catalyst 9136
Search vendor "Cisco" for product "Catalyst 9136"
--
Safe
Cisco
Search vendor "Cisco"
Catalyst 9130 Firmware
Search vendor "Cisco" for product "Catalyst 9130 Firmware"
< 17.6.6
Search vendor "Cisco" for product "Catalyst 9130 Firmware" and version " < 17.6.6"
-
Affected
in Cisco
Search vendor "Cisco"
Catalyst 9130
Search vendor "Cisco" for product "Catalyst 9130"
--
Safe
Cisco
Search vendor "Cisco"
Catalyst 9124 Firmware
Search vendor "Cisco" for product "Catalyst 9124 Firmware"
< 17.6.6
Search vendor "Cisco" for product "Catalyst 9124 Firmware" and version " < 17.6.6"
-
Affected
in Cisco
Search vendor "Cisco"
Catalyst 9124
Search vendor "Cisco" for product "Catalyst 9124"
--
Safe