Description
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.

This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network requests to an affected device. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to reload, resulting in a DoS condition.
Published: 2023-09-27
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-24381 A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network requests to an affected device. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to reload, resulting in a DoS condition.
History

Thu, 21 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Catalyst 9105i Catalyst 9105w Catalyst 9115 Catalyst 9120 Catalyst 9124d Catalyst 9124e Catalyst 9124i Catalyst 9130 Catalyst 9136 Catalyst 9162 Catalyst 9164 Catalyst 9166 Catalyst 9166d1 Catalyst 9800-40 Catalyst 9800-80 Catalyst 9800-cl Catalyst 9800-l Catalyst Iw6300 Esw6300 Ios Xe Iw9167eh-x-ap Iw9167eh-x-urwb Iw9167eh-x-wgb Iw9167ih-x-ap
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-21T21:43:32.060Z

Reserved: 2022-10-27T18:47:50.367Z

Link: CVE-2023-20202

cve-icon Vulnrichment

Updated: 2024-08-02T09:05:35.862Z

cve-icon NVD

Status : Modified

Published: 2023-09-27T18:15:11.177

Modified: 2024-11-21T07:40:49.307

Link: CVE-2023-20202

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses