CVE-2007-4011

Cisco Wireless LAN Controller Software - Denial of Service via Crafted Unicast ARP Request

Title source: llm
STIX 2.1

Description

Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software before 3.2 20070727, 4.0 before 20070727, and 4.1 before 4.1.180.0 allows remote attackers to cause a denial of service (traffic amplification or ARP storm) via a crafted unicast ARP request that (1) has a destination MAC address unknown to the Layer-2 infrastructure, aka CSCsj69233; or (2) occurs during Layer-3 roaming across IP subnets, aka CSCsj70841.

References (6)

Core 6
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2636
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26161
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35576
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25043
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018444

Scores

EPSS 0.0163
EPSS Percentile 73.8%

Details

Status published
Products (5)
cisco/wireless_lan_controller_software 3.2
cisco/wireless_lan_controller_software 3.2.116.21
cisco/wireless_lan_controller_software 4.0
cisco/wireless_lan_controller_software 4.0.155.0
cisco/wireless_lan_controller_software 4.1
Published Jul 26, 2007
Tracked Since Feb 18, 2026