CVE-2015-6341
published 2015-10-25CVE-2015-6341: The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a denial of…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.99%
78.5th percentile
The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a denial of service (client disconnection) via unspecified vectors, aka Bug ID CSCuw10610.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wireless_lan_controller | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-26rm-6fp3-xxhj: The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7
ghsa_unreviewed·2022-05-17
CVE-2015-6341 [MEDIUM] GHSA-26rm-6fp3-xxhj: The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7
The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a denial of service (client disconnection) via unspecified vectors, aka Bug ID CSCuw10610.
Cisco
Cisco Wireless LAN Controller Client Disconnection Vulnerability
vendor_cisco·2015-10-17·CVSS 5.0
CVE-2015-6341 [MEDIUM] CWE-264 Cisco Wireless LAN Controller Client Disconnection Vulnerability
Cisco Wireless LAN Controller Client Disconnection Vulnerability
A vulnerability in the Web Management GUI of the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, remote attacker to trigger client disconnection.
The vulnerability is due to a lack of access control to the Cisco WLC Web Management GUI. An attacker could exploit this vulnerability by connecting to the IP address of the Cisco WLC and triggering client disconnections. The attacker must reach the Cisco WLC management IP address on port 80 or port 443 via its wired interface.
Cisco has not released software updates that address this vulnerability. A workaround that mitigates this vulnerability is available. This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/cont
Cisco
Cisco Wireless LAN Controller Client Disconnection Vulnerability
vendor_cisco
CVE-2015-6341 Cisco Wireless LAN Controller Client Disconnection Vulnerability
CVE-2015-6341: Cisco Wireless LAN Controller Client Disconnection Vulnerability
A vulnerability in the Web Management GUI of the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, remote attacker to trigger client disconnection. The vulnerability is due to a lack of access control to the Cisco WLC Web Management GUI. An attacker could exploit this vulnerability by connecting to the IP address of the Cisco WLC and triggering client disconnections. The attacker must reach the Cisco WLC management IP address on port 80 or port 443 via its wired interface. Cisco has not released software updates that address this vulnerability. A workaround that mitigates this vulnerability is available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-10-25
Published