CVE-2015-6258
published 2015-08-22CVE-2015-6258: The Internet Access Point Protocol (IAPP) module on Cisco Wireless LAN Controller (WLC) devices with software 8.1(104.37) allows remote attackers to trigger…
PriorityP430medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.97%
78.3th percentile
The Internet Access Point Protocol (IAPP) module on Cisco Wireless LAN Controller (WLC) devices with software 8.1(104.37) allows remote attackers to trigger incorrect traffic forwarding via crafted IPv6 packets, aka Bug ID CSCuv40033.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wireless_lan_controller_software | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-82fc-gv4r-v2jq: The Internet Access Point Protocol (IAPP) module on Cisco Wireless LAN Controller (WLC) devices with software 8
ghsa_unreviewed·2022-05-17
CVE-2015-6258 [MEDIUM] CWE-20 GHSA-82fc-gv4r-v2jq: The Internet Access Point Protocol (IAPP) module on Cisco Wireless LAN Controller (WLC) devices with software 8
The Internet Access Point Protocol (IAPP) module on Cisco Wireless LAN Controller (WLC) devices with software 8.1(104.37) allows remote attackers to trigger incorrect traffic forwarding via crafted IPv6 packets, aka Bug ID CSCuv40033.
Cisco
Cisco Wireless LAN Controller IPv6 IAPP WIPS Report Vulnerability
vendor_cisco·2015-08-21·CVSS 5.0
CVE-2015-6258 [MEDIUM] CWE-20 Cisco Wireless LAN Controller IPv6 IAPP WIPS Report Vulnerability
Cisco Wireless LAN Controller IPv6 IAPP WIPS Report Vulnerability
A vulnerability in the Internet Access Point Protocol (IAPP) module of the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, remote attacker to cause network traffic to be forwarded to an unexpected destination network.
The vulnerability is due to improper input validation of the IPv6 packet. An attacker could exploit this vulnerability by sending crafted IPv6 packets to the WLC interface. An exploit could allow the attacker to send traffic to an unexpected destination on a remote sub-network.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit this vulnerability, the attacker would need to send crafted IPv6 packets to the targeted device, making exploitation
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-22
Published