Vulnerability Description
A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain parameters within 802.11 frames. An attacker could exploit this vulnerability by sending a wireless 802.11 association request frame with crafted parameters to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of an affected device, resulting in a DoS condition.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Business 150Ax Firmware | < 10.3.2.0 |
| Cisco | Business 150Ax | - |
| Cisco | Business 151Axm Firmware | < 10.3.2.0 |
| Cisco | Business 151Axm | - |
| Cisco | Catalyst 9105Ax Firmware | < 10.3.2.0 |
| Cisco | Catalyst 9105Ax | - |
| Cisco | Catalyst 9105Axi Firmware | < 10.3.2.0 |
| Cisco | Catalyst 9105Axi | - |
| Cisco | Catalyst 9105Axw Firmware | < 10.3.2.0 |
| Cisco | Catalyst 9105Axw | - |
| Cisco | Catalyst 9105I Firmware | < 10.3.2.0 |
| Cisco | Catalyst 9105I | - |
| Cisco | Catalyst 9105W Firmware | < 10.3.2.0 |
| Cisco | Catalyst 9105W | - |
| Cisco | Catalyst 9115 Firmware | < 10.3.2.0 |
| Cisco | Catalyst 9115 | - |
| Cisco | Catalyst 9115Ax Firmware | < 10.3.2.0 |
| Cisco | Catalyst 9115Ax | - |
| Cisco | Catalyst 9115Axe Firmware | < 10.3.2.0 |
| Cisco | Catalyst 9115Axe | - |
Related Weaknesses (CWE)
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ciVendor Advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ciVendor Advisory
FAQ
What is CVE-2023-20112?
CVE-2023-20112 is a vulnerability with a CVSS score of 7.4 (HIGH). A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to i...
How severe is CVE-2023-20112?
CVE-2023-20112 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-20112?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Business 150Ax Firmware, Cisco Business 150Ax, Cisco Business 151Axm Firmware, Cisco Business 151Axm, Cisco Catalyst 9105Ax Firmware.