PT-2017-9991 · Cisco · Cisco Wireless Lan Controller+1

Publicado

2017-04-05

·

Atualizado

2017-07-12

·

CVE-2016-9195

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Cisco Wireless LAN Controller version 8.3.102.0
Description A vulnerability in RADIUS Change of Authorization (CoA) request processing could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition by disconnecting a single connection. The issue is due to a lack of proper input validation of the RADIUS CoA packet header. An attacker could exploit this by sending a crafted RADIUS CoA packet to a targeted device, allowing them to disconnect a connection through the WLC unexpectedly.
Recommendations For Cisco Wireless LAN Controller version 8.3.102.0, update to one of the following fixed releases: 8.4(1.49), 8.3(111.0), 8.3(108.0), or 8.3(104.24), 8.3(102.3).

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9195

Produtos afetados

Cisco Wireless Lan Controller
Cisco Wls