CVE-2023-20226
A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to the mishandling of a crafted packet stream through the AppQoE or UTD application. An attacker could exploit this vulnerability by sending a crafted packet stream through an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- EPSS probability
- 0.18%
- CWE
- CWE-456
- Published
- 2023-09-27
- Last modified
- 2026-03-13
Affected products
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
- Cisco Cisco IOS XE Software
Weakness type
Related vulnerabilities
- CVE-2024-54131 — Kolide Agent Privilege Escalation (Windows, Versions >= 1.5.3, < 1.12.3)
- CVE-2024-9780 — Missing Initialization of a Variable in Wireshark
- CVE-2024-32878 — Use of Uninitialized Variable Vulnerability in llama.cpp
- CVE-2021-40403 — An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality...
- CVE-2021-34703 — Cisco IOS and IOS XE Software Link Layer Discovery Protocol Denial of Service Vulnerability
- CVE-2019-3836 — It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer...
- CVE-2018-14641 — A security flaw was found in the ip_frag_reasm() function in net/ipv4/ip_fragment.c in the Linux...