MEDIUM · 4.7

CVE-2023-20268

A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device.  This v...

Vulnerability Description

A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device.  This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A sustained attack could lead to the disruption of the Control and Provisioning of Wireless Access Points (CAPWAP) tunnel and intermittent loss of wireless client traffic.

CVSS Score

4.7

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
CiscoWireless Lan Controller Software< 8.10.190.0
CiscoCatalyst 9800 Embedded Wireless Controller Firmware< 17.3.8
CiscoCatalyst 9800 Embedded Wireless Controller-
CiscoBusiness 150Ax Firmware< 10.6.2.0
CiscoBusiness 150Ax-
CiscoBusiness 151Axm Firmware< 10.6.2.0
CiscoBusiness 151Axm-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-20268?

CVE-2023-20268 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device.&nbsp; This v...

How severe is CVE-2023-20268?

CVE-2023-20268 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-20268?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Wireless Lan Controller Software, Cisco Catalyst 9800 Embedded Wireless Controller Firmware, Cisco Catalyst 9800 Embedded Wireless Controller, Cisco Business 150Ax Firmware, Cisco Business 150Ax.