Cisco Wireless LAN Controller HTTP Authorization Denial of Service Vulnerability
BID:35805
Info
Cisco Wireless LAN Controller HTTP Authorization Denial of Service Vulnerability
| Bugtraq ID: | 35805 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-1164 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2009 12:00AM |
| Updated: | Jul 27 2009 06:05PM |
| Credit: | Christoph Bott |
| Vulnerable: |
Cisco WLC Modules for Integrated Services Routers 0 Cisco Wireless Services Modules (WiSM) 0 Cisco Wireless LAN Control 5.2 Cisco Wireless LAN Control 5.1 Cisco Wireless LAN Control 5.0 Cisco Wireless LAN Control 4.2 M Cisco Wireless LAN Control 4.2 Cisco Catalyst 3750G 0 Cisco 5500 Wireless LAN Controller (WLC) 0 Cisco 4404 Wireless LAN Controller (WLC) 0 Cisco 4402 Wireless LAN Controller (WLC) 0 Cisco 4400 Wireless LAN Controller (WLC) 0 Cisco 4400 Wireless LAN Controller (WLC) 0 Cisco 4200 Wireless LAN Controller (WLC) 0 Cisco 4100 Wireless LAN Controller (WLC) 0 Cisco 2106 Wireless LAN Controller (WLC) 0 Cisco 2100 Wireless LAN Controller (WLC) 0 Cisco 2100 Wireless LAN Controller (WLC) 0 Cisco 2006 Wireless LAN Controller (WLC) 0 Cisco 2000 Wireless LAN Controller (WLC) 0 Cisco 1500 |
| Not Vulnerable: |
Cisco Wireless LAN Control 6.0.182 .0 Cisco Wireless LAN Control 5.2.193 .0 Cisco Wireless LAN Control 4.2.207 .0 |
Discussion
Cisco Wireless LAN Controller HTTP Authorization Denial of Service Vulnerability
Cisco Wireless LAN Controller is prone to a denial-of-service vulnerability when handling specially crafted HTTP requests.
An attacker can exploit this issue to trigger an affected device to reboot, causing denial-of-service conditions.
This issue affects Cisco Wireless LAN Controller 4402 (software release 5.1.151.0); other versions and devices may be affected as well.
Cisco Wireless LAN Controller is prone to a denial-of-service vulnerability when handling specially crafted HTTP requests.
An attacker can exploit this issue to trigger an affected device to reboot, causing denial-of-service conditions.
This issue affects Cisco Wireless LAN Controller 4402 (software release 5.1.151.0); other versions and devices may be affected as well.
Exploit / POC
Cisco Wireless LAN Controller HTTP Authorization Denial of Service Vulnerability
Attackers can use readily available network utilities or a browser to exploit this issue.
The following exploit is available:
Attackers can use readily available network utilities or a browser to exploit this issue.
The following exploit is available:
Solution / Fix
Cisco Wireless LAN Controller HTTP Authorization Denial of Service Vulnerability
Solution:
Vendor updates are available. Please see the referenced advisory for details.
Solution:
Vendor updates are available. Please see the referenced advisory for details.
References
Cisco Wireless LAN Controller HTTP Authorization Denial of Service Vulnerability
References:
References:
- Cisco Homepage (Cisco )
- Cisco WLC 4402 Denial-of-Service vulnerability (SySS security advisories -- Christoph Bott)
- Cisco WLC 4402 Denial-of-Service vulnerability (SySS security advisories -- Christoph Bott
) - Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controll (Cisco)