{"id":"CVE-2023-20176","title":"Cisco Aironet Access Points Denial of Service","summary":"A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service.\r\n\r\nThis vulnerability is due to overuse of AP resources. An attacke…","severity":"medium","cvss":5.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L","cvssSource":"vendor","vendor":"Cisco","product":"Cisco Aironet Access Point Software","affected":["aironet_access_point_software","aironet_access_point_software_ios_xe_controller"],"published":"2023-09-27","updated":"2023-09-27","sourceUpdated":"2023-09-27T16:00:00+00:00","source":"CSAF","sourceUrl":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-click-ap-dos-wdcXkvnQ","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-click-ap-dos-wdcXkvnQ"},{"url":"https://software.cisco.com"}],"tags":["csaf","vendor-advisory","cisco"],"epss":0.00653,"epssPercentile":0.49862,"ingestedAt":"2026-09-08T15:58:18.538Z","slug":"CVE-2023-20176","body":"## Overview\n\nA vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service.\r\n\r\nThis vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as a wireless client and sending a high rate of traffic over an extended period of time. A successful exploit could allow the attacker to cause the Datagram TLS (DTLS) session to tear down and reset, causing a denial of service (DoS) condition.\r\n\r\nCisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.\n\n## Vendor advisories\n\n- **cisco-sa-click-ap-dos-wdcXkvnQ** · Cisco · affected: Cisco Aironet Access Point Software, Cisco Aironet Access Point Software (IOS XE Controller) · updated 2023-09-27 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-click-ap-dos-wdcXkvnQ)\n\n**Cisco Catalyst 9100 Access Points Denial of Service Vulnerability**. Released 2023-09-27.\n\nAffected:\n\n- Cisco Aironet Access Point Software\n- Cisco Aironet Access Point Software (IOS XE Controller)\n\n## Remediation\n\nCisco has released software updates that address this vulnerability. https://software.cisco.com","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":31.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}