CVE-2009-1166
published 2009-07-29CVE-2009-1166: The administrative web interface on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0 and 5.x before 5.2.191.0, as used in Cisco 1500…
PriorityP337high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.60%
73.1th percentile
The administrative web interface on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0 and 5.x before 5.2.191.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Modules (WiSM), WLC Modules for Integrated Services Routers, and Catalyst 3750G Integrated Wireless LAN Controllers, allows remote attackers to cause a denial of service (device reload) via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCsy27708.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | catalyst | — | — |
| cisco | wireless_lan_controllers | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v2jh-2f88-8jr3: The administrative web interface on the Cisco Wireless LAN Controller (WLC) platform 4
ghsa_unreviewed·2022-05-02
CVE-2009-1166 [HIGH] GHSA-v2jh-2f88-8jr3: The administrative web interface on the Cisco Wireless LAN Controller (WLC) platform 4
The administrative web interface on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0 and 5.x before 5.2.191.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Modules (WiSM), WLC Modules for Integrated Services Routers, and Catalyst 3750G Integrated Wireless LAN Controllers, allows remote attackers to cause a denial of service (device reload) via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCsy27708.
Cisco
Multiple Vulnerabilities in Cisco Wireless LAN Controllers
vendor_cisco·2009-07-27·CVSS 10.0
CVE-2009-1164 [CRITICAL] CWE-399 Multiple Vulnerabilities in Cisco Wireless LAN Controllers
Multiple Vulnerabilities in Cisco Wireless LAN Controllers
Multiple vulnerabilities exist in the Cisco Wireless LAN Controller
(WLC) platforms. This security advisory outlines the details of the following
vulnerabilities:
Malformed HTTP or HTTPS authentication response denial of service
vulnerability
SSH connections denial of service vulnerability
Crafted HTTP or HTTPS request denial of service vulnerability
Crafted HTTP or HTTPS request unauthorized configuration modification
vulnerability
Cisco has released software updates that address these vulnerabilities.
This advisory is posted at:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090727-wlc
Cisco
Multiple Vulnerabilities in Cisco Wireless LAN Controllers
vendor_cisco
CVE-2009-1166 Multiple Vulnerabilities in Cisco Wireless LAN Controllers
CVE-2009-1166: Multiple Vulnerabilities in Cisco Wireless LAN Controllers
Multiple vulnerabilities exist in the Cisco Wireless LAN Controller (WLC) platforms. This security advisory outlines the
CWE: CWE-399, CWE-94, CWE-399, CWE-94
Bug IDs: CSCsx03715, CSCsw40789, CSCsy27708, CSCsy44672, CSCsw40789
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.cisco.com/en/US/products/products_security_advisory09186a0080adb3d7.shtmlhttp://www.securitytracker.com/id?1022605http://www.vupen.com/english/advisories/2009/2021http://www.cisco.com/en/US/products/products_security_advisory09186a0080adb3d7.shtmlhttp://www.securitytracker.com/id?1022605http://www.vupen.com/english/advisories/2009/2021
2009-07-29
Published