cbcvebase.

Cisco Wireless Lan Controller vulnerabilities

25 known vulnerabilities affecting cisco/cisco_wireless_lan_controller.

Total CVEs
25
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM14

Vulnerabilities

Page 1 of 2
CVE-2022-20695P1CRITICALCVSS 10.0vn/a2022-04-15
CVE-2022-20695 [CRITICAL] CWE-303 CVE-2022-20695: A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This vulnerability is due to the improper implementation of the password validation algorithm. An attacker cou
nvd
CVE-2019-15276P3MEDIUMCVSS 6.5PoC≥ unspecified, < n/a2019-11-26
CVE-2019-15276 [MEDIUM] CWE-20 CVE-2019-15276: A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-pri A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTTP parsing engine to handle specially crafted URLs. An attacker could exploit this vulnerabil
nvd
CVE-2020-3492P3HIGHCVSS 8.6vn/a2020-09-24
CVE-2020-3492 [HIGH] CWE-20 CVE-2020-3492: A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisc A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers and Cisco AireOS Software for Cisco Wireless LAN Controllers (WLC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to i
nvd
CVE-2019-1797P3HIGHCVSS 8.8≥ unspecified, < 8.3.150.0≥ unspecified, < 8.5.135.0+1 more2019-04-18
CVE-2019-1797 [HIGH] CWE-352 CVE-2019-1797: A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Softwar A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on the device with the privileges of the user, including modifying the device configuration. The vulnerability is due to
nvd
CVE-2018-0442P3HIGHCVSS 7.5vn/a2018-10-17
CVE-2018-0442 [HIGH] CWE-200 CVE-2018-0442: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol componen A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. The vulnerability is due to insufficient condition checks in the
nvd
CVE-2018-0382P3HIGHCVSS 7.5≥ unspecified, < 8.5(144.5)2019-04-17
CVE-2018-0382 [HIGH] CWE-287 CVE-2018-0382: A vulnerability in the session identification management functionality of the web-based interface of A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not properly clear previously assigned session
nvd
CVE-2018-0417P3HIGHCVSS 7.8vn/a2018-10-17
CVE-2018-0417 [HIGH] CWE-264 CVE-2018-0417: A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could all A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to perform certain operations within the GUI that are not normally available to that user on the CLI. The vulnerability is due to incorrect parsing of a specific TACACS attribute received in the TACACS response from the
nvd
CVE-2018-0443P3HIGHCVSS 7.5vn/a2018-10-17
CVE-2018-0443 [HIGH] CWE-399 CVE-2018-0443: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol componen A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper input validation on fields within CAPWAP Discovery Request packets by the
nvd
CVE-2020-3273P3HIGHCVSS 7.5vn/a2020-04-15
CVE-2020-3273 [HIGH] CWE-119 CVE-2020-3273: A vulnerability in the 802.11 Generic Advertisement Service (GAS) frame processing function of Cisco A vulnerability in the 802.11 Generic Advertisement Service (GAS) frame processing function of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS). The vulnerability is due to incomplete input validation of the 802.11 GAS frames that ar
nvd
CVE-2021-1419P3HIGHCVSS 7.8vn/a2021-09-23
CVE-2021-1419 [HIGH] CWE-284 CVE-2021-1419: A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A network administrator user could exploi
nvd
CVE-2018-0420P3MEDIUMCVSS 6.5vn/a2018-10-17
CVE-2018-0420 [MEDIUM] CWE-22 CVE-2018-0420: A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an authenticated, remote attacker to view sensitive information. The issue is due to improper sanitization of user-supplied input in HTTP request parameters that describe filenames and pathnames. An attacker could exploit this vulnerability by using director
nvd
CVE-2019-15262P3HIGHCVSS 7.5≥ unspecified, < n/a2019-10-16
CVE-2019-15262 [HIGH] CWE-20 CVE-2019-15262: A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the SSH process is not properly deleted when an SSH connection to the device is disconnected. A
nvd
CVE-2025-20191P3HIGHCVSS 7.4v8.10.112.0v8.8.120.0+82 more2025-05-07
CVE-2025-20191 [HIGH] CWE-805 CVE-2025-20191: A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS X A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the incorrect h
nvd
CVE-2018-0416P4MEDIUMCVSS 5.3vn/a2018-10-17
CVE-2018-0416 [MEDIUM] CWE-20 CVE-2018-0416: A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could all A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to incomplete input and validation checking mechanisms in the web-based interface URL request. An attacker co
nvd
CVE-2019-1799P4MEDIUMCVSS 6.5≥ unspecified, < 8.2.170.0≥ unspecified, < 8.3.150.0+1 more2019-04-18
CVE-2019-1799 [MEDIUM] CWE-399 CVE-2019-1799: A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit
nvd
CVE-2019-1796P4MEDIUMCVSS 6.5≥ unspecified, < 8.2.170.0≥ unspecified, < 8.3.150.0+1 more2019-04-18
CVE-2019-1796 [MEDIUM] CWE-399 CVE-2019-1796: A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit
nvd
CVE-2019-1800P4MEDIUMCVSS 6.5≥ unspecified, < 8.2.170.0≥ unspecified, < 8.3.150.0+1 more2019-04-18
CVE-2019-1800 [MEDIUM] CWE-399 CVE-2019-1800: A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit
nvd
CVE-2022-20769P4MEDIUMCVSS 6.5vn/a2022-09-30
CVE-2022-20769 [MEDIUM] CWE-787 CVE-2022-20769: A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS So A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error validation. An attacker could exploit this vulnerability by sending crafted pa
nvd
CVE-2018-0248P4MEDIUMCVSS 4.9≥ unspecified, < 8.3.150.0≥ unspecified, < 8.5.140.0+1 more2019-04-17
CVE-2018-0248 [MEDIUM] CWE-20 CVE-2018-0248: A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WL A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could allow an aUTHENTICated, remote attacker to cause the device to reload unexpectedly during device configuration when the administrator is using this GUI, causing a denial of service (DoS) condition on an affected device. The attacker wou
nvd
CVE-2018-15395P4MEDIUMCVSS 5.4vn/a2018-10-17
CVE-2018-15395 [MEDIUM] CWE-284 CVE-2018-15395: A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Co A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, adjacent attacker to gain network access to a Cisco TrustSec domain. Under normal circumstances, this access should be prohibited. The vulnerability is due to the dynamic assignment of Security Gro
nvd
Cisco Wireless Lan Controller vulnerabilities | cvebase