ZeroHour

CVE-2023-20112

CVSS 3.1
6.5 medium
EPSS
<1%p23
Published
()
Modified
Description

A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain parameters within 802.11 frames. An attacker could exploit this vulnerability by sending a wireless 802.11 association request frame with crafted parameters to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of an affected device, resulting in a DoS condition.

Vendors
cisco
Products
business 150ax firmware, business 151axm firmware, catalyst 9105ax firmware, catalyst 9105axi firmware, catalyst 9105axw firmware, catalyst 9105i firmware, catalyst 9105w firmware, catalyst 9115 firmware, catalyst 9115ax firmware, catalyst 9115axe firmware, catalyst 9115axi firmware, catalyst 9117 firmware
Weakness
CWE-126, CWE-125
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.