{"id":"CVE-2023-20112","title":"Cisco Access Point Software Association Request Denial of Service Vulnerability (CVE-2023-20112)","summary":"A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to insufficient validation of certain pa…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","cvssSource":"vendor","vendor":"Cisco","product":"Cisco Aironet Access Point Software (IOS XE Controller)","affected":["aironet_access_point_software_ios_xe_controller","aironet_access_point_software","business_wireless_access_point_software"],"published":"2023-03-22","updated":"2023-03-22","sourceUpdated":"2023-03-22T16:00:00+00:00","source":"CSAF","sourceUrl":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ap-assoc-dos-D2SunWK2","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ap-assoc-dos-D2SunWK2"},{"url":"https://software.cisco.com"}],"tags":["csaf","vendor-advisory","cisco"],"epss":0.00303,"epssPercentile":0.23225,"ingestedAt":"2026-09-08T15:58:18.538Z","slug":"CVE-2023-20112","body":"## Overview\n\nA vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to insufficient validation of certain parameters within 802.11 frames. An attacker could exploit this vulnerability by sending a wireless 802.11 association request frame with crafted parameters to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of an affected device, resulting in a DoS condition.\r\n\r\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.\n\n## Vendor advisories\n\n- **cisco-sa-ap-assoc-dos-D2SunWK2** · Cisco · affected: Cisco Aironet Access Point Software (IOS XE Controller), Cisco Aironet Access Point Software, Cisco Business Wireless Access Point Software · updated 2023-03-22 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ap-assoc-dos-D2SunWK2)\n\n**Cisco Access Point Software Association Request Denial of Service Vulnerability**. Released 2023-03-22.\n\nAffected:\n\n- Cisco Aironet Access Point Software (IOS XE Controller)\n- Cisco Aironet Access Point Software\n- Cisco Business Wireless Access Point Software\n\n## Remediation\n\nCisco has released software updates that address this vulnerability. https://software.cisco.com","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}