cbcvebase.
CVE-2007-2039
published 2007-04-16

CVE-2007-2039: The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a…

PriorityP420medium6.1CVSS 2.0
AVAACLAuNCNINAC
EPSS
1.21%
65.2th percentile
The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug IDs CSCsg15901 and CSCsh10841.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscowireless_lan_controller_and_cisco_lightweight_access_points
ciscowireless_lan_controller_software>= 3.2 < 3.2.171.53.2.171.5
ciscowireless_lan_controller_software>= 4.0 < 4.0.206.04.0.206.0
ciscowireless_lan_controller_software>= 4.1 < 4.1.171.04.1.171.0

CVSS provenance

nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.