HIGH · 7.8

CVE-2009-0059

The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x be...

Vulnerability Description

The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow remote attackers to cause a denial of service (device reload) via a web authentication (aka WebAuth) session that includes a malformed POST request to login.html.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
Cisco4400 Wireless Lan Controller4.1
CiscoCatalyst 3750 Series Integrated Wireless Lan Controller4.1
CiscoCatalyst 6500 Series Integrated Wireless Lan Controller4.1
CiscoCatalyst 7600 Series Wireless Lan Controller4.1
CiscoWireless Lan Controller Software4.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-0059?

CVE-2009-0059 is a vulnerability with a CVSS score of 7.8 (HIGH). The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x be...

How severe is CVE-2009-0059?

CVE-2009-0059 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-0059?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco 4400 Wireless Lan Controller, Cisco Catalyst 3750 Series Integrated Wireless Lan Controller, Cisco Catalyst 6500 Series Integrated Wireless Lan Controller, Cisco Catalyst 7600 Series Wireless Lan Controller, Cisco Wireless Lan Controller Software.