Cisco Wireless Lan Controller vulnerabilities
35 known vulnerabilities affecting cisco/cisco_wireless_lan_controller.
Total CVEs
35
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH16MEDIUM18
Vulnerabilities
Page 1 of 2
CVE-2025-20191HIGHCVSS 7.4v8.10.112.0v8.8.120.0+82 more2025-05-07
CVE-2025-20191 [HIGH] CWE-805 CVE-2025-20191: A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS X
A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to the incorrect h
cvelistv5nvd
CVE-2023-20251MEDIUMCVSS 5.3v8.10.162.0v8.10.151.0+6 more2023-09-27
CVE-2023-20251 [MEDIUM] CWE-401 CVE-2023-20251: A vulnerability in the memory buffer of Cisco Wireless LAN Controller (WLC) AireOS Software could al
A vulnerability in the memory buffer of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause memory leaks that could eventually lead to a device reboot.
This vulnerability is due to memory leaks caused by multiple clients connecting under specific conditions. An attacker could exploit this vu
cvelistv5nvd
CVE-2022-20769MEDIUMCVSS 6.5vn/a2022-09-30
CVE-2022-20769 [MEDIUM] CWE-787 CVE-2022-20769: A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS So
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error validation. An attacker could exploit this vulnerability by sending crafted pa
cvelistv5nvd
CVE-2022-20695CRITICALCVSS 10.0vn/a2022-04-15
CVE-2022-20695 [CRITICAL] CWE-303 CVE-2022-20695: A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This vulnerability is due to the improper implementation of the password validation algorithm. An attacker cou
cvelistv5nvd
CVE-2021-1419HIGHCVSS 7.8vn/a2021-09-23
CVE-2021-1419 [HIGH] CWE-284 CVE-2021-1419: A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A network administrator user could exploi
cvelistv5nvd
CVE-2020-3492HIGHCVSS 8.6vn/a2020-09-24
CVE-2020-3492 [HIGH] CWE-20 CVE-2020-3492: A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisc
A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers and Cisco AireOS Software for Cisco Wireless LAN Controllers (WLC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to i
cvelistv5nvd
CVE-2020-3273HIGHCVSS 7.5vn/a2020-04-15
CVE-2020-3273 [HIGH] CWE-119 CVE-2020-3273: A vulnerability in the 802.11 Generic Advertisement Service (GAS) frame processing function of Cisco
A vulnerability in the 802.11 Generic Advertisement Service (GAS) frame processing function of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS). The vulnerability is due to incomplete input validation of the 802.11 GAS frames that ar
cvelistv5nvd
CVE-2019-15276MEDIUMCVSS 6.5PoC≥ unspecified, < n/a2019-11-26
CVE-2019-15276 [MEDIUM] CWE-20 CVE-2019-15276: A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-pri
A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTTP parsing engine to handle specially crafted URLs. An attacker could exploit this vulnerabil
cvelistv5nvd
CVE-2019-15262HIGHCVSS 7.5≥ unspecified, < n/a2019-10-16
CVE-2019-15262 [HIGH] CWE-20 CVE-2019-15262: A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC)
A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the SSH process is not properly deleted when an SSH connection to the device is disconnected. A
cvelistv5nvd
CVE-2019-15266MEDIUMCVSS 4.4≥ unspecified, < n/a2019-10-16
CVE-2019-15266 [MEDIUM] CWE-22 CVE-2019-15266: A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authentica
A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line parameters that describe filenames. An attacker could exploit this vulnerability by using dire
cvelistv5nvd
CVE-2019-1797HIGHCVSS 8.8≥ unspecified, < 8.3.150.0≥ unspecified, < 8.5.135.0+1 more2019-04-18
CVE-2019-1797 [HIGH] CWE-352 CVE-2019-1797: A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Softwar
A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on the device with the privileges of the user, including modifying the device configuration. The vulnerability is due to
cvelistv5nvd
CVE-2019-1800MEDIUMCVSS 6.5≥ unspecified, < 8.2.170.0≥ unspecified, < 8.3.150.0+1 more2019-04-18
CVE-2019-1800 [MEDIUM] CWE-399 CVE-2019-1800: A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit
cvelistv5nvd
CVE-2019-1805MEDIUMCVSS 4.3≥ unspecified, < 8.5(140.0)2019-04-18
CVE-2019-1805 [MEDIUM] CWE-284 CVE-2019-1805: A vulnerability in certain access control mechanisms for the Secure Shell (SSH) server implementatio
A vulnerability in certain access control mechanisms for the Secure Shell (SSH) server implementation for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to access a CLI instance on an affected device. The vulnerability is due to a lack of proper input- and validation-checking mechanisms for inbound SSH c
cvelistv5nvd
CVE-2019-1799MEDIUMCVSS 6.5≥ unspecified, < 8.2.170.0≥ unspecified, < 8.3.150.0+1 more2019-04-18
CVE-2019-1799 [MEDIUM] CWE-399 CVE-2019-1799: A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit
cvelistv5nvd
CVE-2019-1830MEDIUMCVSS 4.9v8.32019-04-18
CVE-2019-1830 [MEDIUM] CWE-20 CVE-2019-1830: A vulnerability in Locally Significant Certificate (LSC) management for the Cisco Wireless LAN Contr
A vulnerability in Locally Significant Certificate (LSC) management for the Cisco Wireless LAN Controller (WLC) could allow an authenticated, remote attacker to cause the device to unexpectedly restart, which causes a denial of service (DoS) condition. The attacker would need to have valid administrator credentials. The vulnerability is due to incorrec
cvelistv5nvd
CVE-2019-1796MEDIUMCVSS 6.5≥ unspecified, < 8.2.170.0≥ unspecified, < 8.3.150.0+1 more2019-04-18
CVE-2019-1796 [MEDIUM] CWE-399 CVE-2019-1796: A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit
cvelistv5nvd
CVE-2018-0382HIGHCVSS 7.5≥ unspecified, < 8.5(144.5)2019-04-17
CVE-2018-0382 [HIGH] CWE-287 CVE-2018-0382: A vulnerability in the session identification management functionality of the web-based interface of
A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not properly clear previously assigned session
cvelistv5nvd
CVE-2018-0248MEDIUMCVSS 4.9≥ unspecified, < 8.3.150.0≥ unspecified, < 8.5.140.0+1 more2019-04-17
CVE-2018-0248 [MEDIUM] CWE-20 CVE-2018-0248: A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WL
A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could allow an aUTHENTICated, remote attacker to cause the device to reload unexpectedly during device configuration when the administrator is using this GUI, causing a denial of service (DoS) condition on an affected device. The attacker wou
cvelistv5nvd
CVE-2018-0417HIGHCVSS 7.8vn/a2018-10-17
CVE-2018-0417 [HIGH] CWE-264 CVE-2018-0417: A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could all
A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to perform certain operations within the GUI that are not normally available to that user on the CLI. The vulnerability is due to incorrect parsing of a specific TACACS attribute received in the TACACS response from the
cvelistv5nvd
CVE-2018-0443HIGHCVSS 7.5vn/a2018-10-17
CVE-2018-0443 [HIGH] CWE-399 CVE-2018-0443: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol componen
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper input validation on fields within CAPWAP Discovery Request packets by the
cvelistv5nvd
1 / 2Next →