CVE-2023-20202: Cisco IOS XE
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network requests to an affected device. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to reload, resulting in a DoS condition.
Affected products
- Cisco IOS XE: version 17.9.1 only; version 17.9.1a only; version 17.9.1w only; version 17.9.1x only; version 17.9.1x1 only; version 17.9.1y only; …
Published 2023-09-27. Last modified 2026-06-17.