PT-2017-9997 · Cisco · Cisco Wireless Lan Controller+1
Published
2017-04-05
·
Updated
2021-04-16
·
CVE-2016-9219
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Wireless LAN Controller (WLC) versions 8.2.121.0 through 8.3.102.0
Description
A vulnerability in IPv6 UDP ingress packet processing could allow an unauthenticated, remote attacker to cause an unexpected reload of the device. The issue is due to incomplete IPv6 UDP header validation. An attacker could exploit this by sending a crafted IPv6 UDP packet to a specific port on the targeted device, impacting the device's availability.
Recommendations
For version 8.2.121.0, update to a fixed software version.
For version 8.3.102.0, update to a fixed software version.
As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Wireless Lan Controller
Cisco Wls