Cisco-SA-20130903-CVE-2013-3474

Cisco Wireless LAN Controller Multiple Parameter Handling Denial of Service Vulnerability

Medium · Updated · Cisco

1 product with CSAF evidence

A vulnerability in the Web Administrator Interface of Cisco Wireless LAN Controllers (WLC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a failure to properly validate certain parameters prior to processing them on the device. An authenticated attacker with an account that is a member of either the Full Manager, Read Only, or Lobby Ambassador managers group could exploit this vulnerability by submitting a request to the affected device that contains a missing or malformed value for specific parameters. An exploit could allow the attacker to crash the device, resulting in a DoS condition, during a system reboot. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement limits the likelihood of a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.