CVE-2023-20176: Cisco Catalyst 9124 Firmware
High severity, CVSS 8.6. EPSS: 0.9% chance of exploitation in the next 30 days.
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as a wireless client and sending a high rate of traffic over an extended period of time. A successful exploit could allow the attacker to cause the Datagram TLS (DTLS) session to tear down and reset, causing a denial of service (DoS) condition.
Affected products
- Cisco Catalyst 9124 Firmware: before 17.6.6 (fixed in 17.6.6)
- Cisco Catalyst 9130 Firmware: before 17.6.6 (fixed in 17.6.6)
- Cisco Catalyst 9136 Firmware: before 17.6.6 (fixed in 17.6.6)
- Cisco Catalyst 9164 Firmware: before 17.6.6 (fixed in 17.6.6)
- Cisco Catalyst 9166 Firmware: before 17.6.6 (fixed in 17.6.6)
Published 2023-09-27. Last modified 2026-06-17.