PT-2007-5225 · Airespace+1 · Airespace 4000+6

Published

2007-07-24

·

Updated

2018-10-30

·

CVE-2007-4012

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software versions prior to 4.1.180.0 Cisco Wireless LAN Controllers (WLC) (affected versions not specified)
Description: The issue allows remote attackers to cause a denial of service (ARP storm) via a broadcast ARP packet that targets the IP address of a known client context. It is related to the handling of Address Resolution Protocol (ARP) packets, which could result in a denial of service (DoS) in certain environments.
Recommendations: For Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software versions prior to 4.1.180.0, update to version 4.1.180.0 or later to resolve the issue. For Cisco Wireless LAN Controllers (WLC) with unspecified affected versions, contact Cisco support for guidance on obtaining and applying the necessary software update to address the vulnerabilities. As a temporary workaround, consider implementing workarounds available to mitigate the effects of these vulnerabilities, such as restricting ARP packet handling or limiting broadcast traffic.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4012

Affected Products

Airespace 4000
Catalyst 3750
Catalyst 6500
Cisco 4100
Cisco 4400
Cisco Wireless Lan Controllers
Cisco Wls