CVE-2013-1102
published 2013-01-24CVE-2013-1102: The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.0, 7.1 and 7.2 before…
PriorityP338high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.82%
76.5th percentile
The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.0, 7.1 and 7.2 before 7.2.110.0, and 7.3 before 7.3.101.0 allows remote attackers to cause a denial of service (device reload) via crafted IP packets, aka Bug ID CSCtx80743.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controllers | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco Wireless LAN Controllers
vendor_cisco·2013-01-24·CVSS 9.0
CVE-2013-1102 [CRITICAL] CWE-264 Multiple Vulnerabilities in Cisco Wireless LAN Controllers
Multiple Vulnerabilities in Cisco Wireless LAN Controllers
The Cisco Wireless LAN Controller (Cisco WLC) product family is affected by the following four vulnerabilities:
Cisco Wireless LAN Controllers Wireless Intrusion Prevention System (wIPS) Denial of Service Vulnerability
Cisco Wireless LAN Controllers Session Initiation Protocol Denial of Service Vulnerability
Cisco Wireless LAN Controllers HTTP Profiling Remote Code Execution Vulnerability
Cisco Wireless LAN Controllers SNMP Unauthorized Access Vulnerability
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ci
Cisco
Cisco Wireless LAN Controllers Wireless Intrusion Prevention System Denial of Service Vulnerability
vendor_cisco·2013-01-23·CVSS 7.8
CVE-2013-1102 [HIGH] CWE-119 Cisco Wireless LAN Controllers Wireless Intrusion Prevention System Denial of Service Vulnerability
Cisco Wireless LAN Controllers Wireless Intrusion Prevention System Denial of Service Vulnerability
Cisco Wireless LAN Controllers (WLC) Wireless Intrusion Prevention System (wIPS) contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper handling of crafted IP packets by the wIPS software component used by the Cisco WLC. An unauthenticated, remote attacker could exploit the vulnerability by sending crafted IP packets to a targeted device. A successful attack could allow the attacker to cause the targeted device to reload, resulting in a DoS condition for legitimate users.
Cisco has confirmed the vulnerability in a security advisory and released software updates.
To exploit this vuln
Cisco
Multiple Vulnerabilities in Cisco Wireless LAN Controllers
vendor_cisco
CVE-2013-1102 Multiple Vulnerabilities in Cisco Wireless LAN Controllers
CVE-2013-1102: Multiple Vulnerabilities in Cisco Wireless LAN Controllers
The Cisco Wireless LAN Controller (Cisco WLC) product family is affected by the following four vulnerabilities: Cisco Wireless LAN Controllers Wireless Intrusion Prevention System (wIPS) Denial of Service Vulnerability Cisco Wireless LAN Controllers Session Initiation Protocol Denial of Service Vulnerability Cisco Wireless LAN Controllers HTTP Profiling Remote Code Execution Vulnerability Cisco Wireless LAN Controllers SNMP Unauthorized Access Vulnerability Cisco has released software updates that address these vulnerabilities.
CWE: CWE-264, CWE-399, CWE-264, CWE-399
Bug IDs: CSCts87659, CSCtx80743, CSCua60653, CSCts87659, CSCtx80743
GHSA
GHSA-3jcc-5246-q6gv: The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) devices with software 7
ghsa_unreviewed·2022-05-17
CVE-2013-1102 [HIGH] GHSA-3jcc-5246-q6gv: The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) devices with software 7
The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.0, 7.1 and 7.2 before 7.2.110.0, and 7.3 before 7.3.101.0 allows remote attackers to cause a denial of service (device reload) via crafted IP packets, aka Bug ID CSCtx80743.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/51965http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130123-wlchttp://www.securityfocus.com/bid/57524http://www.securitytracker.com/id/1028027http://secunia.com/advisories/51965http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130123-wlchttp://www.securityfocus.com/bid/57524http://www.securitytracker.com/id/1028027
2013-01-24
Published