Lucene search

K
cveCiscoCVE-2019-15262
HistoryOct 16, 2019 - 7:15 p.m.

CVE-2019-15262

2019-10-1619:15:13
CWE-20
CWE-404
cisco
web.nvd.nist.gov
71
cisco
wlc
ssh
vulnerability
dos
nvd
cve-2019-15262

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

52.6%

A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the SSH process is not properly deleted when an SSH connection to the device is disconnected. An attacker could exploit this vulnerability by repeatedly opening SSH connections to an affected device. A successful exploit could allow the attacker to exhaust system resources by initiating multiple SSH connections to the device that are not effectively terminated, which could result in a DoS condition.

Affected configurations

Nvd
Node
cisco5520_wireless_lan_controller_firmwareRange8.5.140.0
AND
cisco5520_wireless_lan_controllerMatch-
Node
cisco5508_wireless_lan_controller_firmwareRange8.5.140.0
AND
cisco5508_wireless_lan_controllerMatch-
VendorProductVersionCPE
cisco5520_wireless_lan_controller_firmware*cpe:2.3:o:cisco:5520_wireless_lan_controller_firmware:*:*:*:*:*:*:*:*
cisco5520_wireless_lan_controller-cpe:2.3:h:cisco:5520_wireless_lan_controller:-:*:*:*:*:*:*:*
cisco5508_wireless_lan_controller_firmware*cpe:2.3:o:cisco:5508_wireless_lan_controller_firmware:*:*:*:*:*:*:*:*
cisco5508_wireless_lan_controller-cpe:2.3:h:cisco:5508_wireless_lan_controller:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cisco Wireless LAN Controller (WLC)",
    "vendor": "Cisco",
    "versions": [
      {
        "lessThan": "n/a",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

52.6%