Cisco Wireless Lan Controller Software vulnerabilities
84 known vulnerabilities affecting cisco/wireless_lan_controller_software.
Total CVEs
84
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH32MEDIUM40LOW1
Vulnerabilities
Page 2 of 5
CVE-2018-0248MEDIUMCVSS 4.9fixed in 8.3.150.0≥ 8.4, < 8.5.140.0+1 more2019-04-17
CVE-2018-0248 [MEDIUM] CWE-20 CVE-2018-0248: A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WL
A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could allow an aUTHENTICated, remote attacker to cause the device to reload unexpectedly during device configuration when the administrator is using this GUI, causing a denial of service (DoS) condition on an affected device. The attacker wou
nvd
CVE-2018-0417HIGHCVSS 7.8v8.7\(1.115\)fixed in 8.2.170.0+1 more2018-10-17
CVE-2018-0417 [HIGH] CWE-264 CVE-2018-0417: A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could all
A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to perform certain operations within the GUI that are not normally available to that user on the CLI. The vulnerability is due to incorrect parsing of a specific TACACS attribute received in the TACACS response from the
nvd
CVE-2018-0442HIGHCVSS 7.5fixed in 8.2.170.0≥ 8.3, < 8.3.140.0+3 more2018-10-17
CVE-2018-0442 [HIGH] CWE-200 CVE-2018-0442: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol componen
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. The vulnerability is due to insufficient condition checks in the
nvd
CVE-2018-0443HIGHCVSS 7.5v8.2\(151.0\)2018-10-17
CVE-2018-0443 [HIGH] CWE-399 CVE-2018-0443: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol componen
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper input validation on fields within CAPWAP Discovery Request packets by the
nvd
CVE-2018-15395MEDIUMCVSS 5.4v8.5\(120.0\)2018-10-17
CVE-2018-15395 [MEDIUM] CWE-284 CVE-2018-15395: A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Co
A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, adjacent attacker to gain network access to a Cisco TrustSec domain. Under normal circumstances, this access should be prohibited. The vulnerability is due to the dynamic assignment of Security Gro
nvd
CVE-2018-0388MEDIUMCVSS 4.8v8.3\(133.0\)v8.3\(135.0\)+1 more2018-10-17
CVE-2018-0388 [MEDIUM] CWE-79 CVE-2018-0388: A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could all
A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web-based interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface.
nvd
CVE-2018-0416MEDIUMCVSS 5.3v8.5\(130.0\)v8.9\(1.52\)2018-10-17
CVE-2018-0416 [MEDIUM] CWE-20 CVE-2018-0416: A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could all
A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to incomplete input and validation checking mechanisms in the web-based interface URL request. An attacker co
nvd
CVE-2018-0420MEDIUMCVSS 6.5v8.2\(151.0\)2018-10-17
CVE-2018-0420 [MEDIUM] CWE-22 CVE-2018-0420: A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an
A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an authenticated, remote attacker to view sensitive information. The issue is due to improper sanitization of user-supplied input in HTTP request parameters that describe filenames and pathnames. An attacker could exploit this vulnerability by using director
nvd
CVE-2018-0252HIGHCVSS 8.6v8.4\(100.0\)v8.5\(107.30\)+2 more2018-05-02
CVE-2018-0252 [HIGH] CWE-399 CVE-2018-0252: A vulnerability in the IP Version 4 (IPv4) fragment reassembly function of Cisco 3500, 5500, and 850
A vulnerability in the IP Version 4 (IPv4) fragment reassembly function of Cisco 3500, 5500, and 8500 Series Wireless LAN Controller Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a corruption of an internal data st
nvd
CVE-2018-0235HIGHCVSS 7.4v8.6\(1.106\)v8.6\(1.114\)2018-05-02
CVE-2018-0235 [HIGH] CWE-20 CVE-2018-0235: A vulnerability in the 802.11 frame validation functionality of the Cisco Wireless LAN Controller (W
A vulnerability in the 802.11 frame validation functionality of the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of certain 802.11 management information ele
nvd
CVE-2018-0245MEDIUMCVSS 5.3v8.3\(133.0\)v8.5\(105.0\)2018-05-02
CVE-2018-0245 [MEDIUM] CWE-200 CVE-2018-0245: A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software
A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to incomplete input and validation checking mechanisms in the REST API URL request. An attacker co
nvd
CVE-2018-0247MEDIUMCVSS 4.7v8.3\(104.105\)2018-05-02
CVE-2018-0247 [MEDIUM] CWE-287 CVE-2018-0247: A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC)
A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic. The vulnerability is due to incorrect implementation of authentication for WebAuth clients in a specific con
nvd
CVE-2016-9219HIGHCVSS 7.5v8.3.102.02017-04-06
CVE-2016-9219 [HIGH] CWE-20 CVE-2016-9219: A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Softw
A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an unexpected reload of the device. The vulnerability is due to incomplete IPv6 UDP header validation. An attacker could exploit this vulnerability by sending a crafted IPv6 UDP packet to a speci
nvd
CVE-2017-3854HIGHCVSS 8.8v6.0199.4v7.41.54+3 more2017-03-15
CVE-2017-3854 [HIGH] CWE-287 CVE-2017-3854: A vulnerability in the mesh code of Cisco Wireless LAN Controller (WLC) software could allow an unau
A vulnerability in the mesh code of Cisco Wireless LAN Controller (WLC) software could allow an unauthenticated, remote attacker to impersonate a WLC in a meshed topology. The vulnerability is due to insufficient authentication of the parent access point in a mesh configuration. An attacker could exploit this vulnerability by forcing the target system t
nvd
CVE-2016-6375MEDIUMCVSS 5.3v8.0.72.140v3.0_base+76 more2016-09-12
CVE-2016-6375 [MEDIUM] CWE-399 CVE-2016-6375: Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and
Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow remote attackers to cause a denial of service (device reload) by sending crafted Inter-Access Point Protocol (IAPP) packets and then sending a traffic stream metrics (TSM) information request over SNMP, aka Bug ID CSCuz40221.
nvd
CVE-2016-1460MEDIUMCVSS 6.5v7.4.121.0v8.0.0.30220.3852016-07-28
CVE-2016-1460 [MEDIUM] CWE-399 CVE-2016-1460: Cisco Wireless LAN Controller (WLC) devices 7.4(121.0) and 8.0(0.30220.385) allow remote attackers t
Cisco Wireless LAN Controller (WLC) devices 7.4(121.0) and 8.0(0.30220.385) allow remote attackers to cause a denial of service via crafted wireless management frames, aka Bug ID CSCun92979.
nvd
CVE-2016-1363CRITICALCVSS 9.8≥ 7.2.0, < 7.4.140.0≥ 7.5.0, < 8.0.115.02016-04-21
CVE-2016-1363 [CRITICAL] CWE-399 CVE-2016-1363: Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2
Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through 8.0 before 8.0.115.0(ED) allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCus25617.
nvd
CVE-2016-1364HIGHCVSS 7.5v7.4.1.54v7.4.100+8 more2016-04-21
CVE-2016-1364 [HIGH] CWE-20 CVE-2016-1364: Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8
Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8.0.110.0(ED) allows remote attackers to cause a denial of service (device reload) via crafted Bonjour traffic, aka Bug ID CSCur66908.
nvd
CVE-2015-6314CRITICALCVSS 9.8v8.0.72.140v8.0_base+4 more2016-01-15
CVE-2015-6314 [CRITICAL] CWE-287 CVE-2015-6314: Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 befor
Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change configuration settings via unspecified vectors, aka Bug ID CSCuw06153.
nvd
CVE-2015-6341MEDIUMCVSS 5.0v7.4.140.0v8.0.120.02015-10-25
CVE-2015-6341 [MEDIUM] CWE-264 CVE-2015-6341: The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8
The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a denial of service (client disconnection) via unspecified vectors, aka Bug ID CSCuw10610.
nvd