A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.

This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network requests to an affected device. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to reload, resulting in a DoS condition.

Project Subscriptions

Vendors Products
Catalyst 9105i Subscribe
Catalyst 9105w Subscribe
Catalyst 9115 Subscribe
Catalyst 9120 Subscribe
Catalyst 9124d Subscribe
Catalyst 9124e Subscribe
Catalyst 9124i Subscribe
Catalyst 9130 Subscribe
Catalyst 9136 Subscribe
Catalyst 9162 Subscribe
Catalyst 9164 Subscribe
Catalyst 9166 Subscribe
Catalyst 9166d1 Subscribe
Catalyst 9800-40 Subscribe
Catalyst 9800-80 Subscribe
Catalyst 9800-cl Subscribe
Catalyst 9800-l Subscribe
Catalyst Iw6300 Subscribe
Esw6300 Subscribe
Iw9167eh-x-ap Subscribe
Iw9167eh-x-urwb Subscribe
Iw9167eh-x-wgb Subscribe
Iw9167ih-x-ap Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-24381 A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network requests to an affected device. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to reload, resulting in a DoS condition.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 21 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-21T21:43:32.060Z

Reserved: 2022-10-27T18:47:50.367Z

Link: CVE-2023-20202

cve-icon Vulnrichment

Updated: 2024-08-02T09:05:35.862Z

cve-icon NVD

Status : Modified

Published: 2023-09-27T18:15:11.177

Modified: 2024-11-21T07:40:49.307

Link: CVE-2023-20202

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses