CVE-2007-2037
published 2007-04-16CVE-2007-2037: Cisco Wireless LAN Controller (WLC) before 3.2.116.21, and 4.0.x before 4.0.155.0, allows remote attackers on a local network to cause a denial of service…
PriorityP411low2.9CVSS 2.0
AVAACMAuNCNINAP
EPSS
0.90%
55.8th percentile
Cisco Wireless LAN Controller (WLC) before 3.2.116.21, and 4.0.x before 4.0.155.0, allows remote attackers on a local network to cause a denial of service (device crash) via malformed Ethernet traffic.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wireless_lan_controller_and_cisco_lightweight_access_points | — | — |
| cisco | wireless_lan_controller_software | >= 3.2 < 3.2.116.21 | 3.2.116.21 |
| cisco | wireless_lan_controller_software | >= 4.0 < 4.0.155.0 | 4.0.155.0 |
CVSS provenance
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:N/A:P
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6wvr-8vfm-q9r8: Cisco Wireless LAN Controller (WLC) before 3
ghsa_unreviewed·2022-05-01
CVE-2007-2037 [LOW] GHSA-6wvr-8vfm-q9r8: Cisco Wireless LAN Controller (WLC) before 3
Cisco Wireless LAN Controller (WLC) before 3.2.116.21, and 4.0.x before 4.0.155.0, allows remote attackers on a local network to cause a denial of service (device crash) via malformed Ethernet traffic.
Cisco
Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
vendor_cisco·2007-04-12·CVSS 10.0
CVE-2007-2036 [CRITICAL] CWE-264 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
The Cisco Wireless LAN Controller (WLC) manages Cisco Aironet access
points using the Lightweight Access Point Protocol (LWAPP). The WLC contains
multiple vulnerabilities that could result in a denial of service (DoS)
condition, information disclosure, or access control list changes, or allow an
attacker to gain full administrative access.
Cisco has made free software available to address these vulnerabilities
for affected customers. There are workarounds available to mitigate the effects
of these vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070412-wlc.
Cisco
Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
vendor_cisco
CVE-2007-2037 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
CVE-2007-2037: Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
The Cisco Wireless LAN Controller (WLC) manages Cisco Aironet access points using the Lightweight Access Point Protocol (LWAPP). The WLC contains multiple vulnerabilities that could result in a denial of service (DoS) condition, information disclosure, or access control list changes, or allow an attacker to gain full administrative access. Cisco has made free software available to address these vulnerabilities for affected customers. There are
CWE: CWE-264, CWE-399, CWE-264, CWE-399
Bug IDs: CSCse02384, CSCsc90179, CSCsg36361, CSCsg15901, CSCsh10841
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://securitytracker.com/id?1017908http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtmlhttp://www.osvdb.org/34135http://www.securityfocus.com/bid/23461http://www.vupen.com/english/advisories/2007/1368https://exchange.xforce.ibmcloud.com/vulnerabilities/33607http://securitytracker.com/id?1017908http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtmlhttp://www.osvdb.org/34135http://www.securityfocus.com/bid/23461http://www.vupen.com/english/advisories/2007/1368https://exchange.xforce.ibmcloud.com/vulnerabilities/33607
2007-04-16
Published