cbcvebase.

Cisco Wireless Lan Controller Software vulnerabilities

84 known vulnerabilities affecting cisco/wireless_lan_controller_software.

Total CVEs
84
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH32MEDIUM40LOW1

Vulnerabilities

Page 3 of 5
CVE-2010-0574P3HIGHCVSS 7.8v3.2v3.2.78.0+44 more2010-09-10
CVE-2010-0574 [HIGH] CVE-2010-0574: Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 3.2 before 3.2.215.0; 4.1 Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 3.2 before 3.2.215.0; 4.1 and 4.2 before 4.2.205.0; 4.1M and 4.2M before 4.2.207.54M; 5.0, 5.1, and 6.0 before 6.0.188.0; and 5.2 before 5.2.193.11 allows remote attackers to cause a denial of service (device reload) via a crafted IKE packet, aka Bug ID CSCta56653.
nvd
CVE-2024-20354P3HIGHCVSS 7.4≥ 8.5.171.0, < 8.6.0.0≥ 8.10.130.0, < 8.10.190.812024-03-27
CVE-2024-20354 [HIGH] CWE-460 CVE-2024-20354: A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Soft A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed frames. An attacker could exploit th
nvd
CVE-2012-0368P4HIGHCVSS 7.8v4.0v4.0.108+44 more2012-03-01
CVE-2012-0368 [HIGH] CWE-399 CVE-2012-0368: The administrative management interface on Cisco Wireless LAN Controller (WLC) devices with software The administrative management interface on Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allows remote attackers to cause a denial of service (device crash) via a malformed URL in an HTTP request, aka Bug ID CSCts81997.
nvd
CVE-2018-0235P4HIGHCVSS 7.4v8.6\(1.106\)v8.6\(1.114\)2018-05-02
CVE-2018-0235 [HIGH] CWE-20 CVE-2018-0235: A vulnerability in the 802.11 frame validation functionality of the Cisco Wireless LAN Controller (W A vulnerability in the 802.11 frame validation functionality of the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of certain 802.11 management information ele
nvd
CVE-2023-20097P4MEDIUMCVSS 6.7fixed in 8.10.183.02023-03-23
CVE-2023-20097 [MEDIUM] CWE-77 CVE-2023-20097: A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to an AP. An attacker with Administrator access to the CLI of the controller
nvd
CVE-2015-6302P4MEDIUMCVSS 5.0v7.0.250.0v7.0.252.02015-09-26
CVE-2015-6302 [MEDIUM] CWE-399 CVE-2015-6302: The RADIUS functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.0(250.0) and The RADIUS functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.0(250.0) and 7.0(252.0) allows remote attackers to disconnect arbitrary sessions via crafted Disconnect-Request UDP packets, aka Bug ID CSCuw29419.
nvd
CVE-2021-1449P4MEDIUMCVSS 6.7fixed in 8.5.171.0≥ 8.6, < 8.10.150.02021-03-24
CVE-2021-1449 [MEDIUM] CWE-284 CVE-2021-1449: A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, loca A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code that manages system startup processes. An attacker could exploit this vulnerability by modifying a specific file that i
nvd
CVE-2018-0245P4MEDIUMCVSS 5.3v8.3\(133.0\)v8.5\(105.0\)2018-05-02
CVE-2018-0245 [MEDIUM] CWE-200 CVE-2018-0245: A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to incomplete input and validation checking mechanisms in the REST API URL request. An attacker co
nvd
CVE-2014-0705P4HIGHCVSS 7.1v7.2v7.2.103.0+6 more2014-03-06
CVE-2014-0705 [HIGH] CWE-399 CVE-2014-0705: The multicast listener discovery (MLD) service on Cisco Wireless LAN Controller (WLC) devices 7.2, 7 The multicast listener discovery (MLD) service on Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, 7.4 before 7.4.121.0, and 7.5, when MLDv2 Snooping is enabled, allows remote attackers to cause a denial of service (device restart) via a malformed IPv6 MLDv2 packet, aka Bug ID CSCuh74233.
nvd
CVE-2018-0416P4MEDIUMCVSS 5.3v8.5\(130.0\)v8.9\(1.52\)2018-10-17
CVE-2018-0416 [MEDIUM] CWE-20 CVE-2018-0416: A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could all A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to incomplete input and validation checking mechanisms in the web-based interface URL request. An attacker co
nvd
CVE-2015-6258P4MEDIUMCVSS 5.0v8.1.104.372015-08-22
CVE-2015-6258 [MEDIUM] CWE-20 CVE-2015-6258: The Internet Access Point Protocol (IAPP) module on Cisco Wireless LAN Controller (WLC) devices with The Internet Access Point Protocol (IAPP) module on Cisco Wireless LAN Controller (WLC) devices with software 8.1(104.37) allows remote attackers to trigger incorrect traffic forwarding via crafted IPv6 packets, aka Bug ID CSCuv40033.
nvd
CVE-2015-0726P4MEDIUMCVSS 6.8v7.0.98.0v7.0.98.218+10 more2015-05-16
CVE-2015-0726 [MEDIUM] CWE-20 CVE-2015-0726: The web administration interface on Cisco Wireless LAN Controller (WLC) devices before 7.0.241, 7.1. The web administration interface on Cisco Wireless LAN Controller (WLC) devices before 7.0.241, 7.1.x through 7.4.x before 7.4.122, and 7.5.x and 7.6.x before 7.6.120 allows remote authenticated users to cause a denial of service (device crash) via unspecified parameters, aka Bug IDs CSCum65159 and CSCum65252.
nvd
CVE-2014-0704P4HIGHCVSS 7.1v4.0v4.0.108+51 more2014-03-06
CVE-2014-0704 [HIGH] CWE-399 CVE-2014-0704: The IGMP implementation on Cisco Wireless LAN Controller (WLC) devices 4.x, 5.x, 6.x, 7.0 before 7.0 The IGMP implementation on Cisco Wireless LAN Controller (WLC) devices 4.x, 5.x, 6.x, 7.0 before 7.0.250.0, 7.1, 7.2, and 7.3, when IGMPv3 Snooping is enabled, allows remote attackers to cause a denial of service (memory over-read and device restart) via a crafted field in an IGMPv3 message, aka Bug ID CSCuh33240.
nvd
CVE-2010-2841P4MEDIUMCVSS 6.8v4.0.108v4.0.155.0+26 more2010-09-10
CVE-2010-2841 [MEDIUM] CVE-2010-2841: Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 4.2 before 4.2.209.0; 4.2M Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 4.2 before 4.2.209.0; 4.2M before 4.2.207.54M; 5.0, 5.1, and 6.0 before 6.0.196.0; and 5.2 before 5.2.193.11 allows remote authenticated users to cause a denial of service (device reload) via crafted HTTP packets that trigger invalid arguments to the emweb component, aka Bug ID CSCtd169
nvd
CVE-2007-2040P4MEDIUMCVSS 6.2≥ 3.2, < 3.2.185.0≥ 4.0, < 4.0.206.02007-04-16
CVE-2007-2040 [MEDIUM] CVE-2007-2040: Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3.2.185.0, and 4.0.x befo Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3.2.185.0, and 4.0.x before 4.0.206.0, have a hard-coded password, which allows attackers with physical access to perform arbitrary actions on the device, aka Bug ID CSCsg15192.
nvd
CVE-2019-1799P4MEDIUMCVSS 6.5≥ 8.3.143.0, < 8.3.150.0≥ 8.5.103.0, < 8.5.131.0+1 more2019-04-18
CVE-2019-1799 [MEDIUM] CWE-399 CVE-2019-1799: A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit
nvd
CVE-2019-1796P4MEDIUMCVSS 6.5≥ 8.3.143.0, < 8.5.150.0≥ 8.7.106.0, < 8.8.100.02019-04-18
CVE-2019-1796 [MEDIUM] CWE-399 CVE-2019-1796: A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit
nvd
CVE-2019-1800P4MEDIUMCVSS 6.5≥ 8.3, < 8.5.150.0≥ 8.6, < 8.8.100.02019-04-18
CVE-2019-1800 [MEDIUM] CWE-399 CVE-2019-1800: A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit
nvd
CVE-2022-20769P4MEDIUMCVSS 6.5fixed in 8.10.171.02022-09-30
CVE-2022-20769 [MEDIUM] CWE-787 CVE-2022-20769: A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS So A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error validation. An attacker could exploit this vulnerability by sending crafted pa
nvd
CVE-2015-0723P4MEDIUMCVSS 6.1v7.5.102.0v7.5.102.11+1 more2015-05-16
CVE-2015-0723 [MEDIUM] CWE-399 CVE-2015-0723: The wireless web-authentication subsystem on Cisco Wireless LAN Controller (WLC) devices 7.5.x and 7 The wireless web-authentication subsystem on Cisco Wireless LAN Controller (WLC) devices 7.5.x and 7.6.x before 7.6.120 allows remote attackers to cause a denial of service (process crash and device restart) via a crafted value, aka Bug ID CSCum03269.
nvd
Cisco Wireless Lan Controller Software vulnerabilities | cvebase