CVE-2016-6376
medium
CVSS v3
6.5
CVSS v2
6.1
VIR risk
6.5
Description
The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device restart) via a malformed wIPS packet, aka Bug ID CSCuz40263.
Predictions
Exploit likelihood
65%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-wlc-2
Application impact
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-wlc-2
- http://www.securityfocus.com/bid/92716
- http://www.securitytracker.com/id/1036720
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-wlc-2
- http://www.securityfocus.com/bid/92716
- http://www.securitytracker.com/id/1036720
CWEs
CWE-399
Verify integrity in audit chain (admin only). AS-IS.