HIGH · 7.8

CVE-2012-0368

The administrative management interface on Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allows remot...

Vulnerability Description

The administrative management interface on Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allows remote attackers to cause a denial of service (device crash) via a malformed URL in an HTTP request, aka Bug ID CSCts81997.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoWireless Lan Controller Software4.0
Cisco2000 Wireless Lan Controller-
Cisco2100 Wireless Lan Controller-
Cisco2106 Wireless Lan Controller-
Cisco2112 Wireless Lan Controller-
Cisco2125 Wireless Lan Controller-
Cisco2500 Wireless Lan Controller-
Cisco2504 Wireless Lan Controller-
Cisco4100 Wireless Lan Controller-
Cisco4400 Wireless Lan Controller-
Cisco4402 Wireless Lan Controller-
Cisco4404 Wireless Lan Controller-
Cisco5508 Wireless Controller-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-0368?

CVE-2012-0368 is a vulnerability with a CVSS score of 7.8 (HIGH). The administrative management interface on Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allows remot...

How severe is CVE-2012-0368?

CVE-2012-0368 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-0368?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Wireless Lan Controller Software, Cisco 2000 Wireless Lan Controller, Cisco 2100 Wireless Lan Controller, Cisco 2106 Wireless Lan Controller, Cisco 2112 Wireless Lan Controller.