CVE-2023-20202
27.09.2023, 18:15
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network requests to an affected device. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to reload, resulting in a DoS condition.Enginsight
Vendor | Product | Version |
---|---|---|
cisco | ios_xe | 17.9.1 |
cisco | ios_xe | 17.9.1a:a |
cisco | ios_xe | 17.9.1w:w |
cisco | ios_xe | 17.9.1x:x |
cisco | ios_xe | 17.9.1x1:x1 |
cisco | ios_xe | 17.9.1y:y |
cisco | ios_xe | 17.9.2 |
cisco | ios_xe | 17.9.2a:a |
cisco | ios_xe | 17.9.2b:b |
cisco | ios_xe | 17.10.1 |
cisco | ios_xe | 17.10.1a:a |
cisco | ios_xe | 17.10.1b:b |
𝑥
= Vulnerable software versions
Common Weakness Enumeration