HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-20226

CVSS 8.6v3.1pub. 2023-09-27upd. 2024-11-21

A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to the mishandling of a crafted packet stream through the AppQoE or UTD application. An attacker could exploit this vulnerability by sending a crafted packet stream through an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • Cisco 1100 4g Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 4gltegb Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 4gltena Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 6g Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4221 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4321 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4321\/k9 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4321\/k9 Rf Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4321\/k9 Ws Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4331 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4331\/k9 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4331\/k9 Rf Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4331\/k9 Ws Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4351 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4351\/k9 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4351\/k9 Rf Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4351\/k9 Ws Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4431 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco C8200 1n 4t

    HW
    Cisco
    all versions
  • Cisco C8200l 1n 4t

    HW
    Cisco
    all versions
  • Cisco C8500l 8s4x

    HW
    Cisco
    all versions
  • Cisco Catalyst 8000v Edge

    APP
    Cisco
    all versions
  • Cisco Catalyst 8300 1n1s 4t2x

    HW
    Cisco
    all versions
  • Cisco Catalyst 8300 1n1s 6t

    HW
    Cisco
    all versions
  • Cisco Catalyst 8300 2n2s 4t2x

    HW
    Cisco
    all versions
  • Cisco Catalyst 8300 2n2s 6t

    HW
    Cisco
    all versions
  • Cisco Catalyst Ir8340

    HW
    Cisco
    all versions
  • Cisco IOS XE

    OS
    Cisco
    17.10.117.10.1a17.7.117.7.1a17.7.217.8.117.8.1a17.9.117.9.1a17.9.217.9.2a
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2023-20198CRITICAL10.0⚠ KEVPL ✓same product

Cisco IOS XE Web UI — nieautoryzowane tworzenie konta z privilege 15

CVE-2018-0151CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w QoS Cisco IOS/IOS XE — RCE i DoS przez UDP 18999

CVE-2017-12240CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w DHCP relay Cisco IOS — RCE bez uwierzytelnienia

CVE-2017-3881CRITICAL9.8⚠ KEVPL ✓same product

RCE w Cisco IOS/IOS XE – podatność protokołu CMP przez Telnet

CVE-2026-20267CRITICAL9.0PL ✓same product

Nieprawidłowa kontrola dostępu w Cisco IOS XE Software (CVE-2026-20267)