CVE-2023-20176: High severity cisco catalyst 9166 firmware vulnerability
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as a wireless client and sending a high rate of traffic over an extended period of time. A successful exploit could allow the attacker to cause the Datagram TLS (DTLS) session to tear down and reset, causing a denial of service (DoS) condition.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Cisco access point software vulnerability?
The vulnerability ID is CVE-2023-20176.
What is the severity rating of CVE-2023-20176?
The severity rating of CVE-2023-20176 is 8.6 (high).
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by connecting to an access point.
Which software versions are affected by CVE-2023-20176?
The Cisco Catalyst 9166, 9164, 9136, 9130, and 9124 firmware versions up to and excluding 17.6.6 are affected.
How can I fix CVE-2023-20176?
Cisco has provided a fix for this vulnerability, which can be found in the reference link provided.