PT-2015-4838 · Cisco · Cisco Wireless Lan Controller+1
Published
2015-05-08
·
Updated
2017-01-06
·
CVE-2015-0723
CVSS v2.0
6.1
Medium
| Vector | AV:A/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Wireless LAN Controller (WLC) versions 7.5.x through 7.6.119
Description
A denial of service issue exists due to improper input sanitization of a certain value supplied by a user prior to authentication. An attacker could exploit this by sending a request that triggers the issue, causing a process crash and device restart. The vulnerability can be exploited by an unauthenticated, adjacent attacker with access to the same broadcast or collision domain as the targeted device.
Recommendations
For versions 7.5.x through 7.6.119, update to a fixed software version, such as 7.6.120 or later, to resolve the issue. As a temporary workaround, consider restricting access to the wireless web authentication subsystem to minimize the risk of exploitation.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Wireless Lan Controller
Cisco Wls