QID 317223

Date Published: 2022-10-04

QID 317223: Cisco Internetwork Operating System (IOS) XE Wireless Controller Software for the Catalyst 9000 Family DHCP Processing Denial of Service (DoS) Vulnerability (cisco-sa-wlc-dhcp-dos-76pCjPxK)

A vulnerability in the DHCP processing functionality of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.

Affected Products
This vulnerability affects the following Cisco products if they are running a vulnerable release of Cisco IOS XE Software and they have the DHCP TLV caching feature enabled:
Catalyst 9800-CL Wireless Controllers for Cloud
Catalyst 9800 Series Wireless Controllers
Note: This QID does not check if DHCP TLV caching feature is enabled.

A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-wlc-dhcp-dos-76pCjPxK for more information.

    CVEs related to QID 317223

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-wlc-dhcp-dos-76pCjPxK URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-dhcp-dos-76pCjPxK