Vulnerability Description
A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device. This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A sustained attack could lead to the disruption of the Control and Provisioning of Wireless Access Points (CAPWAP) tunnel and intermittent loss of wireless client traffic.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Wireless Lan Controller Software | < 8.10.190.0 |
| Cisco | Catalyst 9800 Embedded Wireless Controller Firmware | < 17.3.8 |
| Cisco | Catalyst 9800 Embedded Wireless Controller | - |
| Cisco | Business 150Ax Firmware | < 10.6.2.0 |
| Cisco | Business 150Ax | - |
| Cisco | Business 151Axm Firmware | < 10.6.2.0 |
| Cisco | Business 151Axm | - |
Related Weaknesses (CWE)
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ciVendor Advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ciVendor Advisory
FAQ
What is CVE-2023-20268?
CVE-2023-20268 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device. This v...
How severe is CVE-2023-20268?
CVE-2023-20268 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-20268?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Wireless Lan Controller Software, Cisco Catalyst 9800 Embedded Wireless Controller Firmware, Cisco Catalyst 9800 Embedded Wireless Controller, Cisco Business 150Ax Firmware, Cisco Business 150Ax.