CVE-2007-2039
published 2007-04-16CVE-2007-2039: The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a…
PriorityP420medium6.1CVSS 2.0
AVAACLAuNCNINAC
EPSS
1.21%
65.2th percentile
The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug IDs CSCsg15901 and CSCsh10841.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wireless_lan_controller_and_cisco_lightweight_access_points | — | — |
| cisco | wireless_lan_controller_software | >= 3.2 < 3.2.171.5 | 3.2.171.5 |
| cisco | wireless_lan_controller_software | >= 4.0 < 4.0.206.0 | 4.0.206.0 |
| cisco | wireless_lan_controller_software | >= 4.1 < 4.1.171.0 | 4.1.171.0 |
CVSS provenance
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gp6r-fmm5-g6jw: The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3
ghsa_unreviewed·2022-05-01
CVE-2007-2039 [MEDIUM] GHSA-gp6r-fmm5-g6jw: The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3
The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug IDs CSCsg15901 and CSCsh10841.
Cisco
Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
vendor_cisco·2007-04-12·CVSS 10.0
CVE-2007-2036 [CRITICAL] CWE-264 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
The Cisco Wireless LAN Controller (WLC) manages Cisco Aironet access
points using the Lightweight Access Point Protocol (LWAPP). The WLC contains
multiple vulnerabilities that could result in a denial of service (DoS)
condition, information disclosure, or access control list changes, or allow an
attacker to gain full administrative access.
Cisco has made free software available to address these vulnerabilities
for affected customers. There are workarounds available to mitigate the effects
of these vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070412-wlc.
Cisco
Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
vendor_cisco
CVE-2007-2039 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
CVE-2007-2039: Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
The Cisco Wireless LAN Controller (WLC) manages Cisco Aironet access points using the Lightweight Access Point Protocol (LWAPP). The WLC contains multiple vulnerabilities that could result in a denial of service (DoS) condition, information disclosure, or access control list changes, or allow an attacker to gain full administrative access. Cisco has made free software available to address these vulnerabilities for affected customers. There are
CWE: CWE-264, CWE-399, CWE-264, CWE-399
Bug IDs: CSCse02384, CSCsc90179, CSCsg36361, CSCsg15901, CSCsh10841
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://securitytracker.com/id?1017908http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtmlhttp://www.osvdb.org/34137http://www.osvdb.org/34139http://www.securityfocus.com/bid/23461http://www.vupen.com/english/advisories/2007/1368https://exchange.xforce.ibmcloud.com/vulnerabilities/33609http://securitytracker.com/id?1017908http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtmlhttp://www.osvdb.org/34137http://www.osvdb.org/34139http://www.securityfocus.com/bid/23461http://www.vupen.com/english/advisories/2007/1368https://exchange.xforce.ibmcloud.com/vulnerabilities/33609
2007-04-16
Published