Description
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network requests to an affected device. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to reload, resulting in a DoS condition.
Scores
CVSS v3
6.1
EPSS
0.0008
EPSS Percentile
23.0%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-789
Status
published
Products (12)
cisco/ios_xe
17.9.1
cisco/ios_xe
17.9.1a
cisco/ios_xe
17.9.1w
cisco/ios_xe
17.9.1x
cisco/ios_xe
17.9.1x1
cisco/ios_xe
17.9.1y
cisco/ios_xe
17.9.2
cisco/ios_xe
17.9.2a
cisco/ios_xe
17.9.2b
cisco/ios_xe
17.10.1
... and 2 more
Published
Sep 27, 2023
Tracked Since
Feb 18, 2026