Memory Leak Vulnerability in Cisco Wireless LAN Controller AireOS Software
CVE-2023-20251
5.3MEDIUM
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 27 September 2023
What is CVE-2023-20251?
A memory leak vulnerability exists in the Cisco Wireless LAN Controller (WLC) AireOS Software, where an adjacent unauthenticated attacker can exploit this weakness by causing multiple clients to connect to an access point. Under specific conditions, this can lead to memory leaks and may ultimately result in the affected device rebooting. This behavior creates a denial of service (DoS) scenario, significantly impacting the availability of the services provided by the device.
Affected Version(s)
Cisco Mobility Express 8.10.183.0
Cisco Mobility Express 8.10.162.0
Cisco Mobility Express 8.10.151.0