Cisco Wireless LAN Controller CVE-2012-0370 'WebAuth' Denial of Service Vulnerability
BID:52220
Info
Cisco Wireless LAN Controller CVE-2012-0370 'WebAuth' Denial of Service Vulnerability
| Bugtraq ID: | 52220 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2012-0370 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 29 2012 12:00AM |
| Updated: | Feb 29 2012 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco Wireless Services Modules (WiSM) 2 Cisco Wireless Services Modules (WiSM) 0 Cisco Wireless LAN Control 7.1 Cisco Wireless LAN Control 7.0 Cisco Wireless LAN Control 6.0 Cisco Wireless LAN Control 5.2 Cisco Wireless LAN Control 5.1 Cisco Wireless LAN Control 5.0 Cisco Wireless LAN Control 4.2 M Cisco Wireless LAN Control 4.2 Cisco Wireless LAN Control 4.1 M Cisco Wireless LAN Control 4.1 Cisco Wireless LAN Control 4.0 Cisco NME-AIR-WLC for ISR 0 Cisco NM-AIR-WLC for ISR 0 Cisco Flex 7500 Cloud Controllers 0 Cisco Catalyst 3750G 0 Cisco 5500 Wireless LAN Controller (WLC) 0 Cisco 500 Wireless Express Mobility Controllers 0 Cisco 4400 Wireless LAN Controller (WLC) 0 Cisco 4100 Wireless LAN Controller (WLC) 0 Cisco 2500 Wireless LAN Controller (WLC) 0 Cisco 2100 Wireless LAN Controller (WLC) 0 Cisco 2000 Wireless LAN Controller (WLC) 0 |
| Not Vulnerable: |
Cisco Wireless LAN Control 7.1.91.0 Cisco Wireless LAN Control 7.0.220.0 |
Discussion
Cisco Wireless LAN Controller CVE-2012-0370 'WebAuth' Denial of Service Vulnerability
Cisco Wireless LAN Controller is prone to a remote denial-of-service vulnerability.
An unauthenticated attacker can exploit this issue to cause an device configured for 'WebAuth' to reload, denying service to legitimate users.
This issue is tracked by Cisco Bug ID CSCtt47435.
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsq24002
Cisco Wireless LAN Controller is prone to a remote denial-of-service vulnerability.
An unauthenticated attacker can exploit this issue to cause an device configured for 'WebAuth' to reload, denying service to legitimate users.
This issue is tracked by Cisco Bug ID CSCtt47435.
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsq24002
Exploit / POC
Cisco Wireless LAN Controller CVE-2012-0370 'WebAuth' Denial of Service Vulnerability
To exploit this issue, attackers can use a browser or readily available network utilities.
To exploit this issue, attackers can use a browser or readily available network utilities.
Solution / Fix
Cisco Wireless LAN Controller CVE-2012-0370 'WebAuth' Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Cisco Wireless LAN Controller CVE-2012-0370 'WebAuth' Denial of Service Vulnerability
References:
References:
- Cisco Homepage (Cisco )
- Multiple Vulnerabilities in Cisco Wireless LAN Controllers (Cisco)