PT-2013-2875 · Cisco · Cisco Wireless Lan Controller+1
Published
2013-01-23
·
Updated
2013-02-02
·
CVE-2013-1102
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Wireless LAN Controller versions 7.0 through 7.0.234.0
Cisco Wireless LAN Controller versions 7.1 through 7.2.109.0
Cisco Wireless LAN Controller versions 7.3 through 7.3.100.0
Description
The issue is related to the improper handling of crafted IP packets by the Wireless Intrusion Prevention System (wIPS) component, which can cause a denial of service (device reload) when exploited by an unauthenticated, remote attacker. The attacker must send crafted IP packets to the targeted device to exploit the vulnerability, likely requiring access to trusted, internal networks.
Recommendations
For Cisco Wireless LAN Controller version 7.0, update to version 7.0.235.0 or later.
For Cisco Wireless LAN Controller versions 7.1 and 7.2, update to version 7.2.110.0 or later.
For Cisco Wireless LAN Controller version 7.3, update to version 7.3.101.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Wireless Lan Controller
Cisco Wls