HIGH · 7.4

CVE-2023-20112

A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to i...

Vulnerability Description

A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain parameters within 802.11 frames. An attacker could exploit this vulnerability by sending a wireless 802.11 association request frame with crafted parameters to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of an affected device, resulting in a DoS condition.

CVSS Score

7.4

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoBusiness 150Ax Firmware< 10.3.2.0
CiscoBusiness 150Ax-
CiscoBusiness 151Axm Firmware< 10.3.2.0
CiscoBusiness 151Axm-
CiscoCatalyst 9105Ax Firmware< 10.3.2.0
CiscoCatalyst 9105Ax-
CiscoCatalyst 9105Axi Firmware< 10.3.2.0
CiscoCatalyst 9105Axi-
CiscoCatalyst 9105Axw Firmware< 10.3.2.0
CiscoCatalyst 9105Axw-
CiscoCatalyst 9105I Firmware< 10.3.2.0
CiscoCatalyst 9105I-
CiscoCatalyst 9105W Firmware< 10.3.2.0
CiscoCatalyst 9105W-
CiscoCatalyst 9115 Firmware< 10.3.2.0
CiscoCatalyst 9115-
CiscoCatalyst 9115Ax Firmware< 10.3.2.0
CiscoCatalyst 9115Ax-
CiscoCatalyst 9115Axe Firmware< 10.3.2.0
CiscoCatalyst 9115Axe-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-20112?

CVE-2023-20112 is a vulnerability with a CVSS score of 7.4 (HIGH). A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to i...

How severe is CVE-2023-20112?

CVE-2023-20112 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-20112?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Business 150Ax Firmware, Cisco Business 150Ax, Cisco Business 151Axm Firmware, Cisco Business 151Axm, Cisco Catalyst 9105Ax Firmware.