CVE-2023-20112: Cisco Access Point Software Association Request Denial of Service Vulnerability
A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain parameters within 802.11 frames. An attacker could exploit this vulnerability by sending a wireless 802.11 association request frame with crafted parameters to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of an affected device, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What devices are affected by CVE-2023-20112?
Affected devices include various Cisco access points running firmware versions up to but not including 10.3.2.0.
What is the impact of CVE-2023-20112?
CVE-2023-20112 can lead to a denial of service (DoS) condition on the affected Cisco access points.
How can I mitigate CVE-2023-20112?
To mitigate CVE-2023-20112, upgrade the Cisco access point systems to a firmware version that is not vulnerable, specifically beyond 10.3.2.0.
Is CVE-2023-20112 exploitable remotely?
CVE-2023-20112 requires an unauthenticated adjacent attacker to exploit the vulnerability.
What is the nature of the flaw in CVE-2023-20112?
The vulnerability stems from insufficient validation of parameters within 802.11 frames in Cisco access point software.