Cisco Wireless Lan Controller Software vulnerabilities
84 known vulnerabilities affecting cisco/wireless_lan_controller_software.
Total CVEs
84
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH32MEDIUM40LOW1
Vulnerabilities
Page 2 of 5
CVE-2018-0443P3HIGHCVSS 7.5v8.2\(151.0\)2018-10-17
CVE-2018-0443 [HIGH] CWE-399 CVE-2018-0443: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol componen
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper input validation on fields within CAPWAP Discovery Request packets by the
nvd
CVE-2012-6007P4MEDIUMCVSS 4.3PoCv7.2.110.02012-12-19
CVE-2012-6007 [MEDIUM] CVE-2012-6007: Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN
Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992.
nvd
CVE-2009-0062P3CRITICALCVSS 9.0v4.2v4.2.173.02009-02-05
CVE-2009-0062 [CRITICAL] CWE-264 CVE-2009-0062: Unspecified vulnerability in the Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless S
Unspecified vulnerability in the Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.2.173.0 allows remote authenticated users to gain privileges via unknown vectors, as demonstrated by escalation from the (1) Lobby Admin and (2) Local Ma
nvd
CVE-2021-1419P3HIGHCVSS 7.8≥ 8.10, < 8.10.151.02021-09-23
CVE-2021-1419 [HIGH] CWE-284 CVE-2021-1419: A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A network administrator user could exploi
nvd
CVE-2018-0420P3MEDIUMCVSS 6.5v8.2\(151.0\)2018-10-17
CVE-2018-0420 [MEDIUM] CWE-22 CVE-2018-0420: A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an
A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an authenticated, remote attacker to view sensitive information. The issue is due to improper sanitization of user-supplied input in HTTP request parameters that describe filenames and pathnames. An attacker could exploit this vulnerability by using director
nvd
CVE-2007-2036P3CRITICALCVSS 10.0v4.12007-04-16
CVE-2007-2036 [CRITICAL] CVE-2007-2036: The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default
The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, and the default read-write community private, which allows remote attackers to read and modify SNMP variables, aka Bug ID CSCse02384.
nvd
CVE-2012-0369P3HIGHCVSS 7.8v6.0v6.0.182.0+8 more2012-03-01
CVE-2012-0369 [HIGH] CWE-399 CVE-2012-0369: Cisco Wireless LAN Controller (WLC) devices with software 6.0 and 7.0 before 7.0.220.0, 7.1 before 7
Cisco Wireless LAN Controller (WLC) devices with software 6.0 and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allow remote attackers to cause a denial of service (device reload) via a sequence of IPv6 packets, aka Bug ID CSCtt07949.
nvd
CVE-2013-1103P3HIGHCVSS 7.8v7.0v7.0.98.0+3 more2013-01-24
CVE-2013-1103 [HIGH] CVE-2013-1103: Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.220.0, 7.1 before 7.1.91.0,
Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allow remote attackers to cause a denial of service (Access Point reload) via crafted SIP packets, aka Bug ID CSCts87659.
nvd
CVE-2010-2843P3CRITICALCVSS 9.0v4.2v4.2.61.0+19 more2010-09-10
CVE-2010-2843 [CRITICAL] CVE-2010-2843: Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated
Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different vulnerability than CVE-2010-2842 and CVE-2010-3033.
nvd
CVE-2010-2842P3CRITICALCVSS 9.0v4.2v4.2.61.0+19 more2010-09-10
CVE-2010-2842 [CRITICAL] CWE-264 CVE-2010-2842: Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated
Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different vulnerability than CVE-2010-2843 and CVE-2010-3033.
nvd
CVE-2010-3033P3CRITICALCVSS 9.0v4.2v4.2.61.0+19 more2010-09-10
CVE-2010-3033 [CRITICAL] CVE-2010-3033: Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated
Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different vulnerability than CVE-2010-2842 and CVE-2010-2843.
nvd
CVE-2013-1102P3HIGHCVSS 7.8v7.0v7.0.98.0+3 more2013-01-24
CVE-2013-1102 [HIGH] CVE-2013-1102: The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) dev
The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.0, 7.1 and 7.2 before 7.2.110.0, and 7.3 before 7.3.101.0 allows remote attackers to cause a denial of service (device reload) via crafted IP packets, aka Bug ID CSCtx80743.
nvd
CVE-2016-1364P3HIGHCVSS 7.5v7.4.1.54v7.4.100+8 more2016-04-21
CVE-2016-1364 [HIGH] CWE-20 CVE-2016-1364: Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8
Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8.0.110.0(ED) allows remote attackers to cause a denial of service (device reload) via crafted Bonjour traffic, aka Bug ID CSCur66908.
nvd
CVE-2015-4224P3HIGHCVSS 7.2v7.0\(240.0\)2015-06-26
CVE-2015-4224 [HIGH] CWE-78 CVE-2015-4224: Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute ar
Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands in a privileged context via crafted CLI commands, aka Bug ID CSCuj39474.
nvd
CVE-2014-0707P3HIGHCVSS 7.8v7.2v7.2.103.0+5 more2014-03-06
CVE-2014-0707 [HIGH] CWE-399 CVE-2014-0707: Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, and 7.4 before 7.4.110.0 allow remote attacker
Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a denial of service (device restart) via a crafted 802.11 Ethernet frame, aka Bug ID CSCuf80681.
nvd
CVE-2014-0706P3HIGHCVSS 7.8v7.2v7.2.103.0+5 more2014-03-06
CVE-2014-0706 [HIGH] CWE-399 CVE-2014-0706: Cisco Wireless LAN Controller (WLC) devices 7.2 before 7.2.115.2, 7.3, and 7.4 before 7.4.110.0 allo
Cisco Wireless LAN Controller (WLC) devices 7.2 before 7.2.115.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a denial of service (device restart) via a crafted 802.11 Ethernet frame, aka Bug ID CSCue87929.
nvd
CVE-2012-0370P3HIGHCVSS 7.8v4.0v4.0.108+44 more2012-03-01
CVE-2012-0370 [HIGH] CWE-399 CVE-2012-0370: Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0 an
Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0 and 7.1 before 7.1.91.0, when WebAuth is enabled, allow remote attackers to cause a denial of service (device reload) via a sequence of (1) HTTP or (2) HTTPS packets, aka Bug ID CSCtt47435.
nvd
CVE-2009-0059P3HIGHCVSS 7.8v4.1v4.2+1 more2009-02-05
CVE-2009-0059 [HIGH] CWE-20 CVE-2009-0059: The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Ci
The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow remote attackers to cause a denial of service (device reload) via a web authentication (aka WebAuth) session that includes a malformed
nvd
CVE-2009-0061P3HIGHCVSS 7.8v4.1v4.2+1 more2009-02-05
CVE-2009-0061 [HIGH] CWE-20 CVE-2009-0061: Unspecified vulnerability in the Wireless LAN Controller (WLC) TSEC driver in the Cisco 4400 WLC, Ci
Unspecified vulnerability in the Wireless LAN Controller (WLC) TSEC driver in the Cisco 4400 WLC, Cisco Catalyst 6500 and 7600 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.1 allows remote attackers to cause a denial of service (device crash or hang) via unk
nvd
CVE-2014-0701P3HIGHCVSS 7.8v7.0v7.0.220.0+8 more2014-03-06
CVE-2014-0701 [HIGH] CWE-399 CVE-2014-0701: Cisco Wireless LAN Controller (WLC) devices 7.0 before 7.0.250.0, 7.2, 7.3, and 7.4 before 7.4.110.0
Cisco Wireless LAN Controller (WLC) devices 7.0 before 7.0.250.0, 7.2, 7.3, and 7.4 before 7.4.110.0 do not properly deallocate memory, which allows remote attackers to cause a denial of service (reboot) by sending WebAuth login requests at a high rate, aka Bug ID CSCuf52361.
nvd