6.5

CVE-2023-20202

A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.

 This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network requests to an affected device. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to reload, resulting in a DoS condition.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Xe Version17.9.1
   CiscoCatalyst 9105i Version-
   CiscoCatalyst 9105w Version-
   CiscoCatalyst 9115 Version-
   CiscoCatalyst 9120 Version-
   CiscoCatalyst 9124d Version-
   CiscoCatalyst 9124e Version-
   CiscoCatalyst 9124i Version-
   CiscoCatalyst 9130 Version-
   CiscoCatalyst 9136 Version-
   CiscoCatalyst 9162 Version-
   CiscoCatalyst 9164 Version-
   CiscoCatalyst 9166 Version-
   CiscoCatalyst 9166d1 Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Iw6300 Version-
   CiscoEsw6300 Version-
   CiscoIw9167eh-x-ap Version-
   CiscoIw9167eh-x-urwb Version-
   CiscoIw9167eh-x-wgb Version-
   CiscoIw9167ih-x-ap Version-
CiscoIos Xe Version17.9.1a
   CiscoCatalyst 9105i Version-
   CiscoCatalyst 9105w Version-
   CiscoCatalyst 9115 Version-
   CiscoCatalyst 9120 Version-
   CiscoCatalyst 9124d Version-
   CiscoCatalyst 9124e Version-
   CiscoCatalyst 9124i Version-
   CiscoCatalyst 9130 Version-
   CiscoCatalyst 9136 Version-
   CiscoCatalyst 9162 Version-
   CiscoCatalyst 9164 Version-
   CiscoCatalyst 9166 Version-
   CiscoCatalyst 9166d1 Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Iw6300 Version-
   CiscoEsw6300 Version-
   CiscoIw9167eh-x-ap Version-
   CiscoIw9167eh-x-urwb Version-
   CiscoIw9167eh-x-wgb Version-
   CiscoIw9167ih-x-ap Version-
CiscoIos Xe Version17.9.1w
   CiscoCatalyst 9105i Version-
   CiscoCatalyst 9105w Version-
   CiscoCatalyst 9115 Version-
   CiscoCatalyst 9120 Version-
   CiscoCatalyst 9124d Version-
   CiscoCatalyst 9124e Version-
   CiscoCatalyst 9124i Version-
   CiscoCatalyst 9130 Version-
   CiscoCatalyst 9136 Version-
   CiscoCatalyst 9162 Version-
   CiscoCatalyst 9164 Version-
   CiscoCatalyst 9166 Version-
   CiscoCatalyst 9166d1 Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Iw6300 Version-
   CiscoEsw6300 Version-
   CiscoIw9167eh-x-ap Version-
   CiscoIw9167eh-x-urwb Version-
   CiscoIw9167eh-x-wgb Version-
   CiscoIw9167ih-x-ap Version-
CiscoIos Xe Version17.9.1x
   CiscoCatalyst 9105i Version-
   CiscoCatalyst 9105w Version-
   CiscoCatalyst 9115 Version-
   CiscoCatalyst 9120 Version-
   CiscoCatalyst 9124d Version-
   CiscoCatalyst 9124e Version-
   CiscoCatalyst 9124i Version-
   CiscoCatalyst 9130 Version-
   CiscoCatalyst 9136 Version-
   CiscoCatalyst 9162 Version-
   CiscoCatalyst 9164 Version-
   CiscoCatalyst 9166 Version-
   CiscoCatalyst 9166d1 Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Iw6300 Version-
   CiscoEsw6300 Version-
   CiscoIw9167eh-x-ap Version-
   CiscoIw9167eh-x-urwb Version-
   CiscoIw9167eh-x-wgb Version-
   CiscoIw9167ih-x-ap Version-
CiscoIos Xe Version17.9.1x1
   CiscoCatalyst 9105i Version-
   CiscoCatalyst 9105w Version-
   CiscoCatalyst 9115 Version-
   CiscoCatalyst 9120 Version-
   CiscoCatalyst 9124d Version-
   CiscoCatalyst 9124e Version-
   CiscoCatalyst 9124i Version-
   CiscoCatalyst 9130 Version-
   CiscoCatalyst 9136 Version-
   CiscoCatalyst 9162 Version-
   CiscoCatalyst 9164 Version-
   CiscoCatalyst 9166 Version-
   CiscoCatalyst 9166d1 Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Iw6300 Version-
   CiscoEsw6300 Version-
   CiscoIw9167eh-x-ap Version-
   CiscoIw9167eh-x-urwb Version-
   CiscoIw9167eh-x-wgb Version-
   CiscoIw9167ih-x-ap Version-
CiscoIos Xe Version17.9.1y
   CiscoCatalyst 9105i Version-
   CiscoCatalyst 9105w Version-
   CiscoCatalyst 9115 Version-
   CiscoCatalyst 9120 Version-
   CiscoCatalyst 9124d Version-
   CiscoCatalyst 9124e Version-
   CiscoCatalyst 9124i Version-
   CiscoCatalyst 9130 Version-
   CiscoCatalyst 9136 Version-
   CiscoCatalyst 9162 Version-
   CiscoCatalyst 9164 Version-
   CiscoCatalyst 9166 Version-
   CiscoCatalyst 9166d1 Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Iw6300 Version-
   CiscoEsw6300 Version-
   CiscoIw9167eh-x-ap Version-
   CiscoIw9167eh-x-urwb Version-
   CiscoIw9167eh-x-wgb Version-
   CiscoIw9167ih-x-ap Version-
CiscoIos Xe Version17.9.2
   CiscoCatalyst 9105i Version-
   CiscoCatalyst 9105w Version-
   CiscoCatalyst 9115 Version-
   CiscoCatalyst 9120 Version-
   CiscoCatalyst 9124d Version-
   CiscoCatalyst 9124e Version-
   CiscoCatalyst 9124i Version-
   CiscoCatalyst 9130 Version-
   CiscoCatalyst 9136 Version-
   CiscoCatalyst 9162 Version-
   CiscoCatalyst 9164 Version-
   CiscoCatalyst 9166 Version-
   CiscoCatalyst 9166d1 Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Iw6300 Version-
   CiscoEsw6300 Version-
   CiscoIw9167eh-x-ap Version-
   CiscoIw9167eh-x-urwb Version-
   CiscoIw9167eh-x-wgb Version-
   CiscoIw9167ih-x-ap Version-
CiscoIos Xe Version17.9.2a
   CiscoCatalyst 9105i Version-
   CiscoCatalyst 9105w Version-
   CiscoCatalyst 9115 Version-
   CiscoCatalyst 9120 Version-
   CiscoCatalyst 9124d Version-
   CiscoCatalyst 9124e Version-
   CiscoCatalyst 9124i Version-
   CiscoCatalyst 9130 Version-
   CiscoCatalyst 9136 Version-
   CiscoCatalyst 9162 Version-
   CiscoCatalyst 9164 Version-
   CiscoCatalyst 9166 Version-
   CiscoCatalyst 9166d1 Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Iw6300 Version-
   CiscoEsw6300 Version-
   CiscoIw9167eh-x-ap Version-
   CiscoIw9167eh-x-urwb Version-
   CiscoIw9167eh-x-wgb Version-
   CiscoIw9167ih-x-ap Version-
CiscoIos Xe Version17.9.2b
   CiscoCatalyst 9105i Version-
   CiscoCatalyst 9105w Version-
   CiscoCatalyst 9115 Version-
   CiscoCatalyst 9120 Version-
   CiscoCatalyst 9124d Version-
   CiscoCatalyst 9124e Version-
   CiscoCatalyst 9124i Version-
   CiscoCatalyst 9130 Version-
   CiscoCatalyst 9136 Version-
   CiscoCatalyst 9162 Version-
   CiscoCatalyst 9164 Version-
   CiscoCatalyst 9166 Version-
   CiscoCatalyst 9166d1 Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Iw6300 Version-
   CiscoEsw6300 Version-
   CiscoIw9167eh-x-ap Version-
   CiscoIw9167eh-x-urwb Version-
   CiscoIw9167eh-x-wgb Version-
   CiscoIw9167ih-x-ap Version-
CiscoIos Xe Version17.10.1
   CiscoCatalyst 9105i Version-
   CiscoCatalyst 9105w Version-
   CiscoCatalyst 9115 Version-
   CiscoCatalyst 9120 Version-
   CiscoCatalyst 9124d Version-
   CiscoCatalyst 9124e Version-
   CiscoCatalyst 9124i Version-
   CiscoCatalyst 9130 Version-
   CiscoCatalyst 9136 Version-
   CiscoCatalyst 9162 Version-
   CiscoCatalyst 9164 Version-
   CiscoCatalyst 9166 Version-
   CiscoCatalyst 9166d1 Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Iw6300 Version-
   CiscoEsw6300 Version-
   CiscoIw9167eh-x-ap Version-
   CiscoIw9167eh-x-urwb Version-
   CiscoIw9167eh-x-wgb Version-
   CiscoIw9167ih-x-ap Version-
CiscoIos Xe Version17.10.1a
   CiscoCatalyst 9105i Version-
   CiscoCatalyst 9105w Version-
   CiscoCatalyst 9115 Version-
   CiscoCatalyst 9120 Version-
   CiscoCatalyst 9124d Version-
   CiscoCatalyst 9124e Version-
   CiscoCatalyst 9124i Version-
   CiscoCatalyst 9130 Version-
   CiscoCatalyst 9136 Version-
   CiscoCatalyst 9162 Version-
   CiscoCatalyst 9164 Version-
   CiscoCatalyst 9166 Version-
   CiscoCatalyst 9166d1 Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Iw6300 Version-
   CiscoEsw6300 Version-
   CiscoIw9167eh-x-ap Version-
   CiscoIw9167eh-x-urwb Version-
   CiscoIw9167eh-x-wgb Version-
   CiscoIw9167ih-x-ap Version-
CiscoIos Xe Version17.10.1b
   CiscoCatalyst 9105i Version-
   CiscoCatalyst 9105w Version-
   CiscoCatalyst 9115 Version-
   CiscoCatalyst 9120 Version-
   CiscoCatalyst 9124d Version-
   CiscoCatalyst 9124e Version-
   CiscoCatalyst 9124i Version-
   CiscoCatalyst 9130 Version-
   CiscoCatalyst 9136 Version-
   CiscoCatalyst 9162 Version-
   CiscoCatalyst 9164 Version-
   CiscoCatalyst 9166 Version-
   CiscoCatalyst 9166d1 Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst Iw6300 Version-
   CiscoEsw6300 Version-
   CiscoIw9167eh-x-ap Version-
   CiscoIw9167eh-x-urwb Version-
   CiscoIw9167eh-x-wgb Version-
   CiscoIw9167ih-x-ap Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.243
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
psirt@cisco.com 6.1 1.6 4
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE-789 Memory Allocation with Excessive Size Value

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.