Cisco Wireless Lan Controller vulnerabilities
12 known vulnerabilities affecting cisco/wireless_lan_controller.
Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM8
Vulnerabilities
Page 1 of 1
CVE-2020-3559HIGHCVSS 8.6≥ 8.9, < 8.10.112.02020-09-24
CVE-2020-3559 [HIGH] CWE-400 CVE-2020-3559: A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote a
A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper handling of clients that are trying to connect to the AP. An attacker could exploit this vulnerability by sending authentication requests from multiple clients to an affec
nvd
CVE-2020-3552HIGHCVSS 7.4≥ 8.6, < 8.10.105.02020-09-24
CVE-2020-3552 [HIGH] CWE-476 CVE-2020-3552: A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could
A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by connecting as a wired client to the E
nvd
CVE-2020-3560HIGHCVSS 8.6≥ 8.9, < 8.10.112.02020-09-24
CVE-2020-3560 [HIGH] CWE-400 CVE-2020-3560: A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker
A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specific packets. An attacker could exploit this vulnerability by sending a series of crafted UDP packets to a specific po
nvd
CVE-2019-1800MEDIUMCVSS 6.5fixed in 8.2.170.02019-04-18
CVE-2019-1800 [MEDIUM] CWE-399 CVE-2019-1800: A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit
nvd
CVE-2019-1799MEDIUMCVSS 6.5fixed in 8.2.170.02019-04-18
CVE-2019-1799 [MEDIUM] CWE-399 CVE-2019-1799: A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit
nvd
CVE-2019-1796MEDIUMCVSS 6.5fixed in 8.2.170.02019-04-18
CVE-2019-1796 [MEDIUM] CWE-399 CVE-2019-1796: A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit
nvd
CVE-2018-0417HIGHCVSS 7.8≥ 8.4, < 8.5.131.02018-10-17
CVE-2018-0417 [HIGH] CWE-264 CVE-2018-0417: A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could all
A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to perform certain operations within the GUI that are not normally available to that user on the CLI. The vulnerability is due to incorrect parsing of a specific TACACS attribute received in the TACACS response from the
nvd
CVE-2016-9195MEDIUMCVSS 5.3v8.3.102.02017-04-07
CVE-2016-9195 [MEDIUM] CWE-399 CVE-2016-9195: A vulnerability in RADIUS Change of Authorization (CoA) request processing in the Cisco Wireless LAN
A vulnerability in RADIUS Change of Authorization (CoA) request processing in the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition by disconnecting a single connection. This vulnerability affects Cisco Wireless LAN Controller running software release 8.3.102.0. More Inform
nvd
CVE-2016-9194MEDIUMCVSS 6.5v5.2.157.0v5.2.169.0+34 more2017-04-06
CVE-2016-9194 [MEDIUM] CWE-399 CVE-2016-9194: A vulnerability in 802.11 Wireless Multimedia Extensions (WME) action frame processing in Cisco Wire
A vulnerability in 802.11 Wireless Multimedia Extensions (WME) action frame processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of the 802.11 WME packet header. An attacker could exploit this vu
nvd
CVE-2016-6376MEDIUMCVSS 6.5v3.0_basev3.1.59.24+76 more2016-09-02
CVE-2016-6376 [MEDIUM] CWE-399 CVE-2016-6376: The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (W
The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device restart) via a malformed wIPS packet, aka Bug ID CSCuz40263.
nvd
CVE-2015-6311MEDIUMCVSS 6.1v7.0\(240.0\)v7.3\(101.0\)+1 more2015-10-08
CVE-2015-6311 [MEDIUM] CWE-399 CVE-2015-6311: Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0), 7.3(101.0), and 7.4(1.19) allo
Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0), 7.3(101.0), and 7.4(1.19) allow remote attackers to cause a denial of service (device outage) by sending malformed 802.11i management data to a managed access point, aka Bug ID CSCub65236.
nvd
CVE-2015-0756MEDIUMCVSS 6.1v7.4\(1.1\)2015-05-29
CVE-2015-0756 [MEDIUM] CWE-20 CVE-2015-0756: Cisco Wireless LAN Controller (WLC) devices with software 7.4(1.1) allow remote attackers to cause a
Cisco Wireless LAN Controller (WLC) devices with software 7.4(1.1) allow remote attackers to cause a denial of service (wireless-networking outage) via crafted TCP traffic on the local network, aka Bug ID CSCug67104.
nvd