Severity
7.1HIGH
EPSS
0.4%
top 39.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 6
Latest updateMay 17

Description

The multicast listener discovery (MLD) service on Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, 7.4 before 7.4.121.0, and 7.5, when MLDv2 Snooping is enabled, allows remote attackers to cause a denial of service (device restart) via a malformed IPv6 MLDv2 packet, aka Bug ID CSCuh74233.

CVSS vector

AV:N/AC:M/C:N/I:N/A:CExploitability: 8.6 | Impact: 6.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-wc39-prpx-832g: The multicast listener discovery (MLD) service on Cisco Wireless LAN Controller (WLC) devices 72022-05-17
CVEList
CVE-2014-0705: The multicast listener discovery (MLD) service on Cisco Wireless LAN Controller (WLC) devices 72014-03-06

📋Vendor Advisories

1
Cisco
Multiple Vulnerabilities in Cisco Wireless LAN Controllers2014-03-06
CVE-2014-0705 (HIGH CVSS 7.1) | The multicast listener discovery (M | cvebase.io