HIGH✓ PATCH🇬🇧 English

CVE-2023-20226

CVSS 8.6v3.1pub. 2023-09-27upd. 2024-11-21

A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to the mishandling of a crafted packet stream through the AppQoE or UTD application. An attacker could exploit this vulnerability by sending a crafted packet stream through an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • Cisco 1100 4g Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1100 4gltegb Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1100 4gltena Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1100 6g Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4221 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4321 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4321\/k9 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4321\/k9 Rf Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4321\/k9 Ws Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4331 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4331\/k9 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4331\/k9 Rf Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4331\/k9 Ws Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4351 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4351\/k9 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4351\/k9 Rf Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4351\/k9 Ws Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 4431 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco C8200 1n 4t

    HW
    Cisco
    wszystkie wersje
  • Cisco C8200l 1n 4t

    HW
    Cisco
    wszystkie wersje
  • Cisco C8500l 8s4x

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 8000v Edge

    APP
    Cisco
    wszystkie wersje
  • Cisco Catalyst 8300 1n1s 4t2x

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 8300 1n1s 6t

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 8300 2n2s 4t2x

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst 8300 2n2s 6t

    HW
    Cisco
    wszystkie wersje
  • Cisco Catalyst Ir8340

    HW
    Cisco
    wszystkie wersje
  • Cisco IOS XE

    OS
    Cisco
    17.10.117.10.1a17.7.117.7.1a17.7.217.8.117.8.1a17.9.117.9.1a17.9.217.9.2a
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
DoS
CWE
Referencje

Powiązane podatności

CVE-2023-20198CRITICAL10.0⚠ KEVPL ✓ten sam produkt

Cisco IOS XE Web UI — nieautoryzowane tworzenie konta z privilege 15

CVE-2018-0151CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Buffer overflow w QoS Cisco IOS/IOS XE — RCE i DoS przez UDP 18999

CVE-2017-12240CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Buffer overflow w DHCP relay Cisco IOS — RCE bez uwierzytelnienia

CVE-2017-3881CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE w Cisco IOS/IOS XE – podatność protokołu CMP przez Telnet

CVE-2026-20267CRITICAL9.0PL ✓ten sam produkt

Nieprawidłowa kontrola dostępu w Cisco IOS XE Software (CVE-2026-20267)