Cisco Wireless LAN Controller HTTP/HTTPS Denial of Service Vulnerability
BID:35818
Info
Cisco Wireless LAN Controller HTTP/HTTPS Denial of Service Vulnerability
| Bugtraq ID: | 35818 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-1166 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2009 12:00AM |
| Updated: | Jul 27 2009 07:05PM |
| Credit: | IBM Research |
| Vulnerable: |
Cisco WLC Modules for Integrated Services Routers 0 Cisco Wireless Services Modules (WiSM) 0 Cisco Wireless LAN Control 5.2 Cisco Wireless LAN Control 5.1 Cisco Wireless LAN Control 5.0 Cisco Wireless LAN Control 4.2 Cisco Wireless LAN Control 4.1 M Cisco Wireless LAN Control 4.1 Cisco Catalyst 3750G 0 Cisco 4404 Wireless LAN Controller (WLC) 0 Cisco 4402 Wireless LAN Controller (WLC) 0 Cisco 4400 Wireless LAN Controller (WLC) 0 Cisco 4400 Wireless LAN Controller (WLC) 0 Cisco 4200 Wireless LAN Controller (WLC) 0 Cisco 4100 Wireless LAN Controller (WLC) 0 Cisco 2106 Wireless LAN Controller (WLC) 0 Cisco 2100 Wireless LAN Controller (WLC) 0 Cisco 2100 Wireless LAN Controller (WLC) 0 Cisco 2006 Wireless LAN Controller (WLC) 0 Cisco 2000 Wireless LAN Controller (WLC) 0 Cisco 1500 |
| Not Vulnerable: |
Cisco Wireless LAN Control 6.0.182 .0 Cisco Wireless LAN Control 5.2.193 .0 Cisco Wireless LAN Control 4.2.207 .0 Cisco Wireless LAN Control 4.2.205 .0 Cisco Wireless LAN Control 4.2.176 .51 |
Discussion
Cisco Wireless LAN Controller HTTP/HTTPS Denial of Service Vulnerability
Cisco Wireless LAN Controller is prone to a denial-of-service vulnerability when handling specially crafted HTTP or HTTPS requests.
An attacker can exploit this issue to trigger an affected device to crash and reload, causing denial-of-service conditions.
This issue is documented by Cisco Bug ID CSCsy27708.
Cisco Wireless LAN Controller is prone to a denial-of-service vulnerability when handling specially crafted HTTP or HTTPS requests.
An attacker can exploit this issue to trigger an affected device to crash and reload, causing denial-of-service conditions.
This issue is documented by Cisco Bug ID CSCsy27708.
Exploit / POC
Cisco Wireless LAN Controller HTTP/HTTPS Denial of Service Vulnerability
Attackers can use readily available network utilities or a browser to exploit this issue.
Attackers can use readily available network utilities or a browser to exploit this issue.
Solution / Fix
Cisco Wireless LAN Controller HTTP/HTTPS Denial of Service Vulnerability
Solution:
Vendor updates are available. Please see the referenced advisory for details.
Solution:
Vendor updates are available. Please see the referenced advisory for details.
References
Cisco Wireless LAN Controller HTTP/HTTPS Denial of Service Vulnerability
References:
References: