CVE-2015-0726
published 2015-05-16CVE-2015-0726: The web administration interface on Cisco Wireless LAN Controller (WLC) devices before 7.0.241, 7.1.x through 7.4.x before 7.4.122, and 7.5.x and 7.6.x before…
PriorityP429medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
2.77%
84.8th percentile
The web administration interface on Cisco Wireless LAN Controller (WLC) devices before 7.0.241, 7.1.x through 7.4.x before 7.4.122, and 7.5.x and 7.6.x before 7.6.120 allows remote authenticated users to cause a denial of service (device crash) via unspecified parameters, aka Bug IDs CSCum65159 and CSCum65252.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Wireless LAN Controller Web Administration Interface Authenticated Remote Denial of Service Vulnerability
vendor_cisco·2015-05-13·CVSS 6.8
CVE-2015-0726 [MEDIUM] CWE-20 Cisco Wireless LAN Controller Web Administration Interface Authenticated Remote Denial of Service Vulnerability
Cisco Wireless LAN Controller Web Administration Interface Authenticated Remote Denial of Service Vulnerability
A vulnerability in the web administration interface of Cisco Wireless LAN Controllers (WLC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to improper validation of certain parameters submitted as part of form requests prior to processing. An attacker could exploit this vulnerability by submitting a crafted request to a targeted device. If successful, the attacker could cause the device to crash, resulting in a DoS condition.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This ac
GHSA
GHSA-46xf-gvq9-5fvh: The web administration interface on Cisco Wireless LAN Controller (WLC) devices before 7
ghsa_unreviewed·2022-05-13
CVE-2015-0726 [MEDIUM] CWE-20 GHSA-46xf-gvq9-5fvh: The web administration interface on Cisco Wireless LAN Controller (WLC) devices before 7
The web administration interface on Cisco Wireless LAN Controller (WLC) devices before 7.0.241, 7.1.x through 7.4.x before 7.4.122, and 7.5.x and 7.6.x before 7.6.120 allows remote authenticated users to cause a denial of service (device crash) via unspecified parameters, aka Bug IDs CSCum65159 and CSCum65252.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-05-16
Published