Cyber Resilience

CVE-2023-20100

Cisco Ios Xe 17.10.1

Published
23 March 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 6.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS Score 0.0077 53th percentile
Risk Priority 52 floored blend · peak EPSS

Summary

CVE-2023-20100 is a medium-severity Use of Multiple Resources with Duplicate Identifier (CWE-694) vulnerability in Cisco Ios Xe. Its CVSS base score is 6.8 (Medium).

Operationally, ranked in the top 47% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

A vulnerability in the access point (AP) joining process of the Control and Provisioning of Wireless Access Points (CAPWAP) protocol of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to cause a denial…

more

of service (DoS) condition on an affected device. This vulnerability is due to a logic error that occurs when certain conditions are met during the AP joining process. An attacker could exploit this vulnerability by adding an AP that is under their control to the network. The attacker then must ensure that the AP successfully joins an affected wireless controller under certain conditions. Additionally, the attacker would need the ability to restart a valid AP that was previously connected to the controller. A successful exploit could allow the attacker to cause the affected device to restart unexpectedly, resulting in a DoS condition.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-20202Same product: Cisco Catalyst 9800-40
CVE-2024-20303Same product: Cisco Catalyst 9800-40
CVE-2025-20190Same product: Cisco Catalyst 9800-40
CVE-2025-20140Same product: Cisco Catalyst 9800-40
CVE-2023-20231Same product: Cisco Catalyst 9800
CVE-2025-20202Same product: Cisco Ios Xe
CVE-2025-20198Same product: Cisco Ios Xe
CVE-2024-20464Same product: Cisco Ios Xe
CVE-2024-20437Same product: Cisco Ios Xe
CVE-2024-20467Same product: Cisco Ios Xe

Affected Assets

cisco
ios xe
17.10.1

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V8.4.1
  • V3.5.4
  • V6.8.1
  • V9.2.4

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

ID.AM-02 mostly match
prevents

Maintaining software/service inventories requires and enforces unique identifiers to avoid collisions.

PR.AA-01 mostly match
prevents

Managing identities and credentials for users/services/hardware directly requires unique identifiers.

ID.AM-08 partial match
prevents

Lifecycle management of assets includes identifier uniqueness as a supporting practice.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

finds

Security testing can detect duplicate identifiers before deployment.

prevents

Identity management processes that enforce unique identifiers directly prevent duplicate resource IDs.

prevents

Secure development lifecycle practices can catch duplicate-ID issues during design and code review.

prevents

Secure coding standards can mandate unique identifier generation and validation.

degrades

Configuration management ensures unique identifiers are assigned and maintained across resources.

References