CVE-2023-20202: Medium severity cisco ios xe vulnerability
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network requests to an affected device. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to reload, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20202?
CVE-2023-20202 is a vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers that could allow a denial of service (DoS) attack.
How does CVE-2023-20202 affect Cisco IOS XE Software?
CVE-2023-20202 affects Cisco IOS XE Software for Wireless LAN Controllers.
What is the severity of CVE-2023-20202?
CVE-2023-20202 has a severity rating of 6.1 (medium).
What is the cause of CVE-2023-20202?
CVE-2023-20202 is caused by improper memory management in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software.
How can I mitigate CVE-2023-20202?
To mitigate CVE-2023-20202, it is recommended to apply the necessary updates or patches provided by Cisco.