|| Hotline : 800 2378 ||  To contact CERT-MU send e-mail on --> info[at]cert-mu.gov.mu ||  To report incident e-mail on --> incident[at]cert-mu.gov.mu || To report Vulnerabilities send e-mail on --> Vulnerability[at]cert-mu.gov.mu ||
    Constituency
    Authority
    Vol. 2, Feb 2012
    Vol. 1, Oct 2011
    World CERTs
    Email Abuse
 
 
Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
 
 
 
 
 
 
 
 
 
 
 


   
 

CERT-MU AD-2009-12

Cisco Wireless LAN Controller SSH and Web Interface Remote Denial of Service Vulnerabilities

Original issue date: 06 August, 2009

Overview

Cisco Wireless LAN Controller software contains vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.

Description

Various activities in Wireless LAN, for example, system-wide wireless LAN functions, such as security policies, intrusion prevention, RF management, quality of service (QoS), and mobility, is administered by Cisco Wireless LAN Controllers (WLCs). The WLC is administered by administrative web console or SSH.

Multiple vulnerabilities have been reported in WLC's remote SSH connection and Web Management interface.

  • All Bind based DNS servers

    A remote user could exploit an error in the SSH server by making crafted requests to the affected system. This could trigger a memory leak and cause the target device to crash.

  • Web Management Interface Malicious http/https Request Remote Denial of Service Vulnerability

    A remote user could exploit the vulnerability in the administrative web console by making crafted requests to the system. These requests could cause the system to reboot, resulting in a DoS condition.
Affected Systems

  • Cisco Wireless LAN Controller versions prior to 4.2.205.0
  • Cisco Wireless LAN Controller versions 5.0 and later
  • Cisco Wireless LAN Controller versions 5.1 and later
  • Cisco Wireless LAN Controller versions prior to 5.2.178.0
  • Cisco Wireless LAN Controller versions 4.1 and later
  • Cisco Wireless LAN Controller versions prior to 5.1.163.0

Impact

Severity Rating: High

Solution

Apply appropriate fixed versions as mentioned in CISCO Security Advisory.
http://www.cisco.com/warp/public/707/cisco-sa-20090727-wlc.shtml

Disclaimer

The information provided herein is on "as is" basis, without warranty of any kind.

Vendor Information

CISCO
http://www.cisco.com/warp/public/707/cisco-sa-20090727-wlc.shtml

CVE Name

CVE-2009-1165
CVE-2009-1166

References


CISCO


http://tools.cisco.com/security/center/viewAlert.x?alertId=18583
http://tools.cisco.com/security/center/viewAlert.x?alertId=18584

Security Tracker


http://securitytracker.com/alerts/2009/Jul/1022605.html

 
 
News & Events
Safer Internet Day 2012
Computer Security Day 2011
Workshop on Cloud Security
Workshop on Mobile Security
Certificate Award Ceremony for Trainings in Information Security Management

  more...
 
Virus Alerts
RSS Feed
 
 
 

Last Updated 20-Jul-2011
Disclaimer Maintained & Hosted by NCB
This site is best viewed in 1024 x 768 resolution. Internet Explorer 6.0 +

09-Jul-2011