PT-2007-5225 · Airespace+1 · Airespace 4000+6

Publicado

2007-07-24

·

Atualizado

2018-10-30

·

CVE-2007-4012

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software versions prior to 4.1.180.0 Cisco Wireless LAN Controllers (WLC) (affected versions not specified)
Description: The issue allows remote attackers to cause a denial of service (ARP storm) via a broadcast ARP packet that targets the IP address of a known client context. It is related to the handling of Address Resolution Protocol (ARP) packets, which could result in a denial of service (DoS) in certain environments.
Recommendations: For Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software versions prior to 4.1.180.0, update to version 4.1.180.0 or later to resolve the issue. For Cisco Wireless LAN Controllers (WLC) with unspecified affected versions, contact Cisco support for guidance on obtaining and applying the necessary software update to address the vulnerabilities. As a temporary workaround, consider implementing workarounds available to mitigate the effects of these vulnerabilities, such as restricting ARP packet handling or limiting broadcast traffic.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-4012

Produtos afetados

Airespace 4000
Catalyst 3750
Catalyst 6500
Cisco 4100
Cisco 4400
Cisco Wireless Lan Controllers
Cisco Wls