CVE-2023-20202 Details
Description
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network requests to an affected device. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to reload, resulting in a DoS condition.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 30, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-789 | Memory Allocation with Excessive Size Value | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco ios xe | 17.9.1 17.9.1a 17.9.1w 17.9.1x 17.9.1x1 17.9.1y 17.9.2 17.9.2a 17.9.2b 17.10.1 17.10.1a 17.10.1b |
CPE
Remediation
| |
| cisco catalyst 9105i | All versions |
CPE
Remediation
| |
| cisco catalyst 9105w | All versions |
CPE
Remediation
| |
| cisco catalyst 9115 | All versions |
CPE
Remediation
| |
| cisco catalyst 9120 | All versions |
CPE
Remediation
| |
| cisco catalyst 9124d | All versions |
CPE
Remediation
| |
| cisco catalyst 9124e | All versions |
CPE
Remediation
| |
| cisco catalyst 9124i | All versions |
CPE
Remediation
| |
| cisco catalyst 9130 | All versions |
CPE
Remediation
| |
| cisco catalyst 9136 | All versions |
CPE
Remediation
| |
| cisco catalyst 9162 | All versions |
CPE
Remediation
| |
| cisco catalyst 9164 | All versions |
CPE
Remediation
| |
| cisco catalyst 9166 | All versions |
CPE
Remediation
| |
| cisco catalyst 9166d1 | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-40 | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-80 | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-cl | All versions |
CPE
Remediation
| |
| cisco catalyst 9800-l | All versions |
CPE
Remediation
| |
| cisco catalyst iw6300 | All versions |
CPE
Remediation
| |
| cisco esw6300 | All versions |
CPE
Remediation
| |
| cisco iw9167eh-x-ap | All versions |
CPE
Remediation
| |
| cisco iw9167eh-x-urwb | All versions |
CPE
Remediation
| |
| cisco iw9167eh-x-wgb | All versions |
CPE
Remediation
| |
| cisco iw9167ih-x-ap | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 25, 2024 | CVE Modified | [email protected] |
| Oct 6, 2023 | Initial Analysis | [email protected] |