Cisco Wireless Lan Controller Software vulnerabilities
84 known vulnerabilities affecting cisco/wireless_lan_controller_software.
Total CVEs
84
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH32MEDIUM40LOW1
Vulnerabilities
Page 4 of 5
CVE-2015-0679P4MEDIUMCVSS 6.1v7.3\(103.8\)v7.4\(110.0\)2015-03-28
CVE-2015-0679 [MEDIUM] CWE-20 CVE-2015-0679: The web-authentication functionality on Cisco Wireless LAN Controller (WLC) devices 7.3(103.8) and 7
The web-authentication functionality on Cisco Wireless LAN Controller (WLC) devices 7.3(103.8) and 7.4(110.0) allows remote attackers to cause a denial of service (device reload) via a malformed password, aka Bug ID CSCui57980.
nvd
CVE-2015-6341P4MEDIUMCVSS 5.0v7.4.140.0v8.0.120.02015-10-25
CVE-2015-6341 [MEDIUM] CWE-264 CVE-2015-6341: The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8
The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a denial of service (client disconnection) via unspecified vectors, aka Bug ID CSCuw10610.
nvd
CVE-2007-4011P4HIGHCVSS 7.1v3.2v3.2.116.21+3 more2007-07-26
CVE-2007-4011 [HIGH] CVE-2007-4011: Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) softwa
Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software before 3.2 20070727, 4.0 before 20070727, and 4.1 before 4.1.180.0 allows remote attackers to cause a denial of service (traffic amplification or ARP storm) via a crafted unicast ARP request that (1) has a destination MAC address unknown to the Layer-2 infrast
nvd
CVE-2015-4215P4MEDIUMCVSS 6.1v7.5.102.02015-06-24
CVE-2015-4215 [MEDIUM] CWE-399 CVE-2015-4215: Cisco Wireless LAN Controller (WLC) devices with software 7.5(102.0) and 7.6(1.62) allow remote atta
Cisco Wireless LAN Controller (WLC) devices with software 7.5(102.0) and 7.6(1.62) allow remote attackers to cause a denial of service (device crash) by triggering an exception during attempted forwarding of unspecified IPv6 packets to a non-IPv6 device, aka Bug ID CSCuj01046.
nvd
CVE-2018-0248P4MEDIUMCVSS 4.9fixed in 8.3.150.0≥ 8.4, < 8.5.140.0+1 more2019-04-17
CVE-2018-0248 [MEDIUM] CWE-20 CVE-2018-0248: A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WL
A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could allow an aUTHENTICated, remote attacker to cause the device to reload unexpectedly during device configuration when the administrator is using this GUI, causing a denial of service (DoS) condition on an affected device. The attacker wou
nvd
CVE-2018-15395P4MEDIUMCVSS 5.4v8.5\(120.0\)2018-10-17
CVE-2018-15395 [MEDIUM] CWE-284 CVE-2018-15395: A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Co
A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, adjacent attacker to gain network access to a Cisco TrustSec domain. Under normal circumstances, this access should be prohibited. The vulnerability is due to the dynamic assignment of Security Gro
nvd
CVE-2007-4012P4HIGHCVSS 7.1v3.2v3.2.116.21+3 more2007-07-26
CVE-2007-4012 [HIGH] CVE-2007-4012: Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) softwa
Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software 4.1 before 4.1.180.0 allows remote attackers to cause a denial of service (ARP storm) via a broadcast ARP packet that "targets the IP address of a known client context", aka CSCsj50374.
nvd
CVE-2016-1460P4MEDIUMCVSS 6.5v7.4.121.0v8.0.0.30220.3852016-07-28
CVE-2016-1460 [MEDIUM] CWE-399 CVE-2016-1460: Cisco Wireless LAN Controller (WLC) devices 7.4(121.0) and 8.0(0.30220.385) allow remote attackers t
Cisco Wireless LAN Controller (WLC) devices 7.4(121.0) and 8.0(0.30220.385) allow remote attackers to cause a denial of service via crafted wireless management frames, aka Bug ID CSCun92979.
nvd
CVE-2016-6375P4MEDIUMCVSS 5.3v8.0.72.140v3.0_base+76 more2016-09-12
CVE-2016-6375 [MEDIUM] CWE-399 CVE-2016-6375: Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and
Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow remote attackers to cause a denial of service (device reload) by sending crafted Inter-Access Point Protocol (IAPP) packets and then sending a traffic stream metrics (TSM) information request over SNMP, aka Bug ID CSCuz40221.
nvd
CVE-2010-0575P4MEDIUMCVSS 5.0v4.2v4.2.61.0+16 more2010-09-10
CVE-2010-0575 [MEDIUM] CWE-264 CVE-2010-0575: Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows r
Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs in the controller CPU, and consequently send network traffic to unintended segments or devices, via unspecified vectors, a different vulnerability than CVE-2010-3034.
nvd
CVE-2010-3034P4MEDIUMCVSS 5.0v4.2v4.2.61.0+16 more2010-09-10
CVE-2010-3034 [MEDIUM] CVE-2010-3034: Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows r
Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs in the controller CPU, and consequently send network traffic to unintended segments or devices, via unspecified vectors, a different vulnerability than CVE-2010-0575.
nvd
CVE-2018-0247P4MEDIUMCVSS 4.7v8.3\(104.105\)2018-05-02
CVE-2018-0247 [MEDIUM] CWE-287 CVE-2018-0247: A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC)
A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic. The vulnerability is due to incorrect implementation of authentication for WebAuth clients in a specific con
nvd
CVE-2023-20056P4MEDIUMCVSS 5.5fixed in 8.10.183.02023-03-23
CVE-2023-20056 [MEDIUM] CWE-78 CVE-2023-20056: A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticat
A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a devi
nvd
CVE-2019-1830P4MEDIUMCVSS 4.9fixed in 8.3.150.0≥ 8.5.131.0, < 8.5.140.0+1 more2019-04-18
CVE-2019-1830 [MEDIUM] CWE-20 CVE-2019-1830: A vulnerability in Locally Significant Certificate (LSC) management for the Cisco Wireless LAN Contr
A vulnerability in Locally Significant Certificate (LSC) management for the Cisco Wireless LAN Controller (WLC) could allow an authenticated, remote attacker to cause the device to unexpectedly restart, which causes a denial of service (DoS) condition. The attacker would need to have valid administrator credentials. The vulnerability is due to incorrec
nvd
CVE-2023-20268P4MEDIUMCVSS 4.7fixed in 8.10.190.02023-09-27
CVE-2023-20268 [MEDIUM] CWE-400 CVE-2023-20268: A vulnerability in the packet processing functionality of Cisco access point (AP) software could all
A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device.
This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a s
nvd
CVE-2009-0058P4MEDIUMCVSS 6.1v4.1v4.2+1 more2009-02-05
CVE-2009-0058 [MEDIUM] CWE-20 CVE-2009-0058: The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Ci
The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.2 allow remote attackers to cause a denial of service (web authentication outage or device reload) via unspecified network traffic, as demonstrated b
nvd
CVE-2013-1141P4MEDIUMCVSS 6.1≤ 7.4.1.54v3.0+55 more2013-02-28
CVE-2013-1141 [MEDIUM] CWE-119 CVE-2013-1141: The mDNS snooping functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.4.1.5
The mDNS snooping functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.4.1.54 and earlier does not properly manage buffers, which allows remote authenticated users to cause a denial of service (device reload) via crafted mDNS packets, aka Bug ID CSCue04153.
nvd
CVE-2019-1805P4MEDIUMCVSS 4.3v8.3\(141.0\)2019-04-18
CVE-2019-1805 [MEDIUM] CWE-284 CVE-2019-1805: A vulnerability in certain access control mechanisms for the Secure Shell (SSH) server implementatio
A vulnerability in certain access control mechanisms for the Secure Shell (SSH) server implementation for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to access a CLI instance on an affected device. The vulnerability is due to a lack of proper input- and validation-checking mechanisms for inbound SSH c
nvd
CVE-2007-2039P4MEDIUMCVSS 6.1≥ 3.2, < 3.2.171.5≥ 4.0, < 4.0.206.0+1 more2007-04-16
CVE-2007-2039 [MEDIUM] CWE-399 CVE-2007-2039: The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x
The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka B
nvd
CVE-2018-0388P4MEDIUMCVSS 4.8v8.3\(133.0\)v8.3\(135.0\)+1 more2018-10-17
CVE-2018-0388 [MEDIUM] CWE-79 CVE-2018-0388: A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could all
A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web-based interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface.
nvd