PT-2019-1987 · Cisco · Cisco Wireless Lan Controller (Wlc)+1

Publicado

2019-04-17

·

Atualizado

2019-10-09

·

CVE-2018-0248

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Wireless LAN Controller (WLC) Software versions prior to 8.3.150.0 Cisco Wireless LAN Controller (WLC) Software versions prior to 8.5.140.0 Cisco Wireless LAN Controller (WLC) Software versions prior to 8.8.111.0
Description A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, remote attacker to cause the device to reload unexpectedly during device configuration, causing a denial of service (DoS) condition on an affected device. The attacker would need to have valid administrator credentials on the device. This vulnerability is due to incomplete input validation for unexpected configuration options that the attacker could submit while accessing the GUI configuration menus. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted user input when using the administrative GUI configuration feature. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Recommendations For versions prior to 8.3.150.0, update to version 8.3.150.0 or later. For versions prior to 8.5.140.0, update to version 8.5.140.0 or later. For versions prior to 8.8.111.0, update to version 8.8.111.0 or later. As a temporary workaround, consider restricting access to the administrative GUI configuration feature until a patch is available.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01680
CVE-2018-0248

Produtos afetados

Cisco Wireless Lan Controller (Wlc)
Cisco Wls