Lucene search

K
ciscoCiscoCISCO-SA-20150513-CVE-2015-0726
HistoryMay 13, 2015 - 4:12 p.m.

Cisco Wireless LAN Controller Web Administration Interface Authenticated Remote Denial of Service Vulnerability

2015-05-1316:12:01
tools.cisco.com
12

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

EPSS

0.001

Percentile

50.2%

A vulnerability in the web administration interface of Cisco Wireless LAN Controllers (WLC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

The vulnerability is due to improper validation of certain parameters submitted as part of form requests prior to processing. An attacker could exploit this vulnerability by submitting a crafted request to a targeted device. If successful, the attacker could cause the device to crash, resulting in a DoS condition.

Cisco has confirmed the vulnerability and released software updates.

To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement decreases the likelihood of a successful exploit.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscowireless_lan_controllerMatch7.0
OR
ciscowireless_lan_controllerMatch7.4
OR
ciscowireless_lan_controllerMatch7.6
OR
ciscowireless_lan_controllerMatchany
OR
ciscowireless_lan_controllerMatch7.0.98.0
OR
ciscowireless_lan_controllerMatch7.0.116.0
OR
ciscowireless_lan_controllerMatch7.0.98.218
OR
ciscowireless_lan_controllerMatch7.0.220.0
OR
ciscowireless_lan_controllerMatch7.4.100.0
OR
ciscowireless_lan_controllerMatch7.4.100.60
OR
ciscowireless_lan_controllerMatch7.4.110.0
OR
ciscowireless_lan_controllerMatch7.4.121.0
OR
ciscowireless_lan_controllerMatch7.6.100.0
OR
ciscowireless_lan_controllerMatch7.6.110.0
VendorProductVersionCPE
ciscowireless_lan_controller7.0cpe:2.3:h:cisco:wireless_lan_controller:7.0:*:*:*:*:*:*:*
ciscowireless_lan_controller7.4cpe:2.3:h:cisco:wireless_lan_controller:7.4:*:*:*:*:*:*:*
ciscowireless_lan_controller7.6cpe:2.3:h:cisco:wireless_lan_controller:7.6:*:*:*:*:*:*:*
ciscowireless_lan_controlleranycpe:2.3:h:cisco:wireless_lan_controller:any:*:*:*:*:*:*:*
ciscowireless_lan_controller7.0.98.0cpe:2.3:h:cisco:wireless_lan_controller:7.0.98.0:*:*:*:*:*:*:*
ciscowireless_lan_controller7.0.116.0cpe:2.3:h:cisco:wireless_lan_controller:7.0.116.0:*:*:*:*:*:*:*
ciscowireless_lan_controller7.0.98.218cpe:2.3:h:cisco:wireless_lan_controller:7.0.98.218:*:*:*:*:*:*:*
ciscowireless_lan_controller7.0.220.0cpe:2.3:h:cisco:wireless_lan_controller:7.0.220.0:*:*:*:*:*:*:*
ciscowireless_lan_controller7.4.100.0cpe:2.3:h:cisco:wireless_lan_controller:7.4.100.0:*:*:*:*:*:*:*
ciscowireless_lan_controller7.4.100.60cpe:2.3:h:cisco:wireless_lan_controller:7.4.100.60:*:*:*:*:*:*:*
Rows per page:
1-10 of 141

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

EPSS

0.001

Percentile

50.2%

Related for CISCO-SA-20150513-CVE-2015-0726