Cisco Wireless Lan Controller Software vulnerabilities
84 known vulnerabilities affecting cisco/wireless_lan_controller_software.
Total CVEs
84
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH32MEDIUM40LOW1
Vulnerabilities
Page 1 of 5
CVE-2019-15276P3MEDIUMCVSS 6.5PoC≥ 8.4, < 8.102019-11-26
CVE-2019-15276 [MEDIUM] CWE-20 CVE-2019-15276: A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-pri
A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTTP parsing engine to handle specially crafted URLs. An attacker could exploit this vulnerabil
nvd
CVE-2011-1613P3HIGHCVSS 7.8PoCv6.0.182.0v6.0.188.0+4 more2011-05-03
CVE-2011-1613 [HIGH] CVE-2011-1613: Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 6.0 before 6.0.200.0, 7.0
Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 6.0 before 6.0.200.0, 7.0 before 7.0.98.216, and 7.0.1xx before 7.0.112.0 allows remote attackers to cause a denial of service (device reload) via a sequence of ICMP packets, aka Bug ID CSCth74426.
nvd
CVE-2016-1363P2CRITICALCVSS 9.8≥ 7.2.0, < 7.4.140.0≥ 7.5.0, < 8.0.115.02016-04-21
CVE-2016-1363 [CRITICAL] CWE-399 CVE-2016-1363: Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2
Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through 8.0 before 8.0.115.0(ED) allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCus25617.
nvd
CVE-2015-6314P3CRITICALCVSS 9.8v8.0.72.140v8.0_base+4 more2016-01-15
CVE-2015-6314 [CRITICAL] CWE-287 CVE-2015-6314: Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 befor
Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change configuration settings via unspecified vectors, aka Bug ID CSCuw06153.
nvd
CVE-2012-5991P3MEDIUMCVSS 6.3PoCv7.2.110.02012-12-19
CVE-2012-5991 [MEDIUM] CVE-2012-5991: screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.1
screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to cause a denial of service (device reload) via a certain buttonClicked value in an internal webauth_type request, aka Bug ID CSCud50209.
nvd
CVE-2014-0703P3CRITICALCVSS 10.0v7.4.100.0v7.4.100.602014-03-06
CVE-2014-0703 [CRITICAL] CWE-362 CVE-2014-0703: Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software wit
Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the administrative HTTP server, which allows remote attackers to bypass intended access restrictions by connecting to an Aironet access point on which this server had been disabled ineffectively, aka Bug ID CSCuf662
nvd
CVE-2013-1104P3CRITICALCVSS 9.0v7.3.101.02013-01-24
CVE-2013-1104 [CRITICAL] CVE-2013-1104: The HTTP Profiling functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.3.10
The HTTP Profiling functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.3.101.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP User-Agent header, aka Bug ID CSCuc15636.
nvd
CVE-2012-5992P4MEDIUMCVSS 6.8PoCv7.2.110.02012-12-19
CVE-2012-5992 [MEDIUM] CWE-352 CVE-2012-5992: Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) de
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via screens/aaa/mgmtuser_create.html or (2) insert XSS sequences via the headline parameter to screens/
nvd
CVE-2017-3854P3HIGHCVSS 8.8v6.0199.4v7.41.54+3 more2017-03-15
CVE-2017-3854 [HIGH] CWE-287 CVE-2017-3854: A vulnerability in the mesh code of Cisco Wireless LAN Controller (WLC) software could allow an unau
A vulnerability in the mesh code of Cisco Wireless LAN Controller (WLC) software could allow an unauthenticated, remote attacker to impersonate a WLC in a meshed topology. The vulnerability is due to insufficient authentication of the parent access point in a mesh configuration. An attacker could exploit this vulnerability by forcing the target system t
nvd
CVE-2024-20271P3HIGHCVSS 8.6fixed in 8.10.190.02024-03-27
CVE-2024-20271 [HIGH] CWE-20 CVE-2024-20271: A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unaut
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this vulnerability by sending a crafted IPv4 pac
nvd
CVE-2018-0252P3HIGHCVSS 8.6v8.4\(100.0\)v8.5\(107.30\)+2 more2018-05-02
CVE-2018-0252 [HIGH] CWE-399 CVE-2018-0252: A vulnerability in the IP Version 4 (IPv4) fragment reassembly function of Cisco 3500, 5500, and 850
A vulnerability in the IP Version 4 (IPv4) fragment reassembly function of Cisco 3500, 5500, and 8500 Series Wireless LAN Controller Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a corruption of an internal data st
nvd
CVE-2019-1797P3HIGHCVSS 8.8fixed in 8.3.150.0≥ 8.5.131.0, < 8.5.150.0+1 more2019-04-18
CVE-2019-1797 [HIGH] CWE-352 CVE-2019-1797: A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Softwar
A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on the device with the privileges of the user, including modifying the device configuration. The vulnerability is due to
nvd
CVE-2018-0442P3HIGHCVSS 7.5fixed in 8.2.170.0≥ 8.3, < 8.3.140.0+3 more2018-10-17
CVE-2018-0442 [HIGH] CWE-200 CVE-2018-0442: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol componen
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. The vulnerability is due to insufficient condition checks in the
nvd
CVE-2021-1437P3HIGHCVSS 7.5≥ 8.10.112.0, < 8.10.142.02021-03-24
CVE-2021-1437 [HIGH] CWE-275 CVE-2021-1437: A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software co
A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial File Transfer Protocol (TFTP) configuration. An attacker could exploit this vulnerability by sen
nvd
CVE-2012-0371P3CRITICALCVSS 9.3v4.0v4.0.108+42 more2012-03-01
CVE-2012-0371 [CRITICAL] CWE-264 CVE-2012-0371: Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.4, w
Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.4, when CPU-based ACLs are enabled, allow remote attackers to read or modify the configuration via unspecified vectors, aka Bug ID CSCtu56709.
nvd
CVE-2020-3560P3HIGHCVSS 8.6fixed in 8.5.161.0≥ 8.6, < 8.8.130.02020-09-24
CVE-2020-3560 [HIGH] CWE-400 CVE-2020-3560: A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker
A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specific packets. An attacker could exploit this vulnerability by sending a series of crafted UDP packets to a specific po
nvd
CVE-2013-1105P3CRITICALCVSS 9.0v7.0v7.0.98.0+6 more2013-01-24
CVE-2013-1105 [CRITICAL] CWE-264 CVE-2013-1105: Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.3, 7.1 and 7.2 before 7
Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.3, 7.1 and 7.2 before 7.2.111.3, and 7.3 before 7.3.101.0 allow remote authenticated users to bypass wireless-management settings and read or modify the device configuration via an SNMP request, aka Bug ID CSCua60653.
nvd
CVE-2016-9219P3HIGHCVSS 7.5v8.3.102.02017-04-06
CVE-2016-9219 [HIGH] CWE-20 CVE-2016-9219: A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Softw
A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an unexpected reload of the device. The vulnerability is due to incomplete IPv6 UDP header validation. An attacker could exploit this vulnerability by sending a crafted IPv6 UDP packet to a speci
nvd
CVE-2018-0382P3HIGHCVSS 7.5v8.1\(111.0\)v8.5\(120.0\)2019-04-17
CVE-2018-0382 [HIGH] CWE-287 CVE-2018-0382: A vulnerability in the session identification management functionality of the web-based interface of
A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not properly clear previously assigned session
nvd
CVE-2018-0417P3HIGHCVSS 7.8v8.7\(1.115\)fixed in 8.2.170.0+1 more2018-10-17
CVE-2018-0417 [HIGH] CWE-264 CVE-2018-0417: A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could all
A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to perform certain operations within the GUI that are not normally available to that user on the CLI. The vulnerability is due to incorrect parsing of a specific TACACS attribute received in the TACACS response from the
nvd
1 / 5Next →