cbcvebase.
CVE-2016-1363
published 2016-04-21

CVE-2016-1363: Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through 8.0…

PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.58%
92.0th percentile
Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through 8.0 before 8.0.115.0(ED) allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCus25617.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscowireless_lan_controller_http_parsing
ciscowireless_lan_controller_software>= 7.2.0 < 7.4.140.07.4.140.0
ciscowireless_lan_controller_software>= 7.5.0 < 8.0.115.08.0.115.0

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a crafted HTTP request targeting the HTTP URL redirect feature of Cisco WLC; monitor for anomalous or oversized HTTP requests directed at WLC management/web interfaces
  • The vulnerability resides specifically in the HTTP URL redirection/redirect feature of Cisco WLC software; focus detection on HTTP redirect handling code paths
  • No authentication is required to exploit this vulnerability; any unauthenticated HTTP request to the WLC should be treated as a potential attack vector
  • Successful exploitation may cause the device to reload (crash/reboot); unexpected WLC reloads should be investigated as potential exploitation attempts
  • ·Affected versions are WLC Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through 8.0 before 8.0.115.0(ED); verify device software version to confirm exposure
  • ·There are no workarounds available for this vulnerability; patching to a fixed release is the only mitigation
  • ·Cisco internal bug tracker reference for this vulnerability is CSCus25617; use this ID when cross-referencing Cisco TAC or field notices

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.