Vulnerability Description
Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software 4.1 before 4.1.180.0 allows remote attackers to cause a denial of service (ARP storm) via a broadcast ARP packet that "targets the IP address of a known client context", aka CSCsj50374.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | 4100 Wireless Lan Controller | All versions |
| Cisco | 4400 Wireless Lan Controller | All versions |
| Cisco | Airespace 4000 Wireless Lan Controller | All versions |
| Cisco | Catalyst 3750 | All versions |
| Cisco | Catalyst 6500 | All versions |
| Cisco | Wireless Lan Controller Software | 3.2 |
References
- http://secunia.com/advisories/26161Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a008088ab28.s
- http://www.securityfocus.com/bid/25043
- http://www.securitytracker.com/id?1018444
- http://www.vupen.com/english/advisories/2007/2636
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35576
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44591
- http://secunia.com/advisories/26161Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a008088ab28.s
- http://www.securityfocus.com/bid/25043
- http://www.securitytracker.com/id?1018444
- http://www.vupen.com/english/advisories/2007/2636
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35576
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44591
FAQ
What is CVE-2007-4012?
CVE-2007-4012 is a vulnerability with a CVSS score of 7.1 (HIGH). Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software 4.1 before 4.1.180.0 allows remote attackers to cause a denial of service (ARP storm) via a broad...
How severe is CVE-2007-4012?
CVE-2007-4012 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4012?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco 4100 Wireless Lan Controller, Cisco 4400 Wireless Lan Controller, Cisco Airespace 4000 Wireless Lan Controller, Cisco Catalyst 3750, Cisco Catalyst 6500.