Lucene search

K
cveCiscoCVE-2014-0705
HistoryMar 06, 2014 - 11:55 a.m.

CVE-2014-0705

2014-03-0611:55:05
CWE-399
cisco
web.nvd.nist.gov
27
cisco
wlc
mldv2
dos
ipv6
vulnerability
mldv2 snooping
denial of service
cve-2014-0705
cscuh74233
nvd

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

6.8

Confidence

Low

EPSS

0.002

Percentile

56.2%

The multicast listener discovery (MLD) service on Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, 7.4 before 7.4.121.0, and 7.5, when MLDv2 Snooping is enabled, allows remote attackers to cause a denial of service (device restart) via a malformed IPv6 MLDv2 packet, aka Bug ID CSCuh74233.

Affected configurations

Nvd
Node
ciscowireless_lan_controller_softwareMatch7.2
OR
ciscowireless_lan_controller_softwareMatch7.2.103.0
OR
ciscowireless_lan_controller_softwareMatch7.2.110.0
OR
ciscowireless_lan_controller_softwareMatch7.3
OR
ciscowireless_lan_controller_softwareMatch7.3.101.0
OR
ciscowireless_lan_controller_softwareMatch7.4.100.0
OR
ciscowireless_lan_controller_softwareMatch7.4.100.60
OR
ciscowireless_lan_controller_softwareMatch7.5
AND
ciscowireless_lan_controller
VendorProductVersionCPE
ciscowireless_lan_controller_software7.2cpe:2.3:o:cisco:wireless_lan_controller_software:7.2:*:*:*:*:*:*:*
ciscowireless_lan_controller_software7.2.103.0cpe:2.3:o:cisco:wireless_lan_controller_software:7.2.103.0:*:*:*:*:*:*:*
ciscowireless_lan_controller_software7.2.110.0cpe:2.3:o:cisco:wireless_lan_controller_software:7.2.110.0:*:*:*:*:*:*:*
ciscowireless_lan_controller_software7.3cpe:2.3:o:cisco:wireless_lan_controller_software:7.3:*:*:*:*:*:*:*
ciscowireless_lan_controller_software7.3.101.0cpe:2.3:o:cisco:wireless_lan_controller_software:7.3.101.0:*:*:*:*:*:*:*
ciscowireless_lan_controller_software7.4.100.0cpe:2.3:o:cisco:wireless_lan_controller_software:7.4.100.0:*:*:*:*:*:*:*
ciscowireless_lan_controller_software7.4.100.60cpe:2.3:o:cisco:wireless_lan_controller_software:7.4.100.60:*:*:*:*:*:*:*
ciscowireless_lan_controller_software7.5cpe:2.3:o:cisco:wireless_lan_controller_software:7.5:*:*:*:*:*:*:*
ciscowireless_lan_controller*cpe:2.3:h:cisco:wireless_lan_controller:*:*:*:*:*:*:*:*

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

6.8

Confidence

Low

EPSS

0.002

Percentile

56.2%