PT-2013-2875 · Cisco · Cisco Wireless Lan Controller+1

Published

2013-01-23

·

Updated

2013-02-02

·

CVE-2013-1102

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Wireless LAN Controller versions 7.0 through 7.0.234.0 Cisco Wireless LAN Controller versions 7.1 through 7.2.109.0 Cisco Wireless LAN Controller versions 7.3 through 7.3.100.0
Description The issue is related to the improper handling of crafted IP packets by the Wireless Intrusion Prevention System (wIPS) component, which can cause a denial of service (device reload) when exploited by an unauthenticated, remote attacker. The attacker must send crafted IP packets to the targeted device to exploit the vulnerability, likely requiring access to trusted, internal networks.
Recommendations For Cisco Wireless LAN Controller version 7.0, update to version 7.0.235.0 or later. For Cisco Wireless LAN Controller versions 7.1 and 7.2, update to version 7.2.110.0 or later. For Cisco Wireless LAN Controller version 7.3, update to version 7.3.101.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2013-1102

Affected Products

Cisco Wireless Lan Controller
Cisco Wls