Description
A vulnerability in 802.11 Wireless Multimedia Extensions (WME) action frame processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of the 802.11 WME packet header. An attacker could exploit this vulnerability by sending malformed 802.11 WME frames to a targeted device. A successful exploit could allow the attacker to cause the WLC to reload unexpectedly. The fixed versions are 8.0.140.0, 8.2.130.0, and 8.3.111.0. Cisco Bug IDs: CSCva86353.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/97424
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1038182
Vendor Advisory x_refsource_confirm
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-wlc
Scores
CVSS v3
6.5
EPSS
0.0078
EPSS Percentile
52.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-399
Status
published
Products (50)
cisco/wireless_lan_controller
5.2.157.0
cisco/wireless_lan_controller
5.2.169.0
cisco/wireless_lan_controller
6.0_base
cisco/wireless_lan_controller
7.0_base
cisco/wireless_lan_controller
7.1_base
cisco/wireless_lan_controller
7.2_base
cisco/wireless_lan_controller
7.3.101.0
cisco/wireless_lan_controller
7.3.103.8
cisco/wireless_lan_controller
7.3.112
cisco/wireless_lan_controller
7.3_base
... and 40 more
Published
Apr 06, 2017
Tracked Since
Feb 18, 2026