Memory Leak Vulnerability in Cisco Wireless LAN Controller AireOS Software
CVE-2023-20251
5.3MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 27 September 2023
Summary
A memory leak vulnerability exists in the Cisco Wireless LAN Controller (WLC) AireOS Software, where an adjacent unauthenticated attacker can exploit this weakness by causing multiple clients to connect to an access point. Under specific conditions, this can lead to memory leaks and may ultimately result in the affected device rebooting. This behavior creates a denial of service (DoS) scenario, significantly impacting the availability of the services provided by the device.
Affected Version(s)
Cisco Mobility Express 8.10.183.0
Cisco Mobility Express 8.10.162.0
Cisco Mobility Express 8.10.151.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved