A vulnerability in the web management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a missing internal handler for the specific request. An attacker could exploit this vulnerability by accessing a specific hidden URL on the GUI web management interface. A successful exploit could allow the attacker to cause a reload of the device, resulting in a DoS condition. This vulnerability affects only the Cisco Wireless LAN Controller 8.3.102.0 release. Cisco Bug IDs: CSCvb48198.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
The product does not handle or incorrectly handles an exceptional condition.
Link | Tags |
---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-wlc3 | vendor advisory |
http://www.securityfocus.com/bid/97421 | third party advisory vdb entry |
http://www.securitytracker.com/id/1038184 | third party advisory vdb entry |