6.5
CVSSv3

CVE-2019-15276

Published: 26/11/2019 Updated: 11/12/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote malicious user to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTTP parsing engine to handle specially crafted URLs. An attacker could exploit this vulnerability by authenticating with low privileges to an affected controller and submitting the crafted URL to the web interface of the affected device. Conversely, an unauthenticated attacker could exploit this vulnerability by persuading a user of the web interface to click the crafted URL. A successful exploit could allow the malicious user to cause an unexpected restart of the device, resulting in a DoS condition.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco wireless lan controller software

Vendor Advisories

A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device The vulnerability exists due to a failure of the HTTP parsing engine to handle specially crafted URLs An attacker could exploit this vulner ...

Exploits

# Exploit Title: Cisco WLC 2504 89 - Denial of Service (PoC) # Google Dork: N/A # Date: 2019-11-25 # Exploit Author: SecuNinja # Vendor Homepage: ciscocom # Software Link: toolsciscocom/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-wlc-dos # Version: 84 to 89 # Tested on: not applicable, works independent from OS # C ...
Cisco WLC 2504 version 89 suffers from a denial of service vulnerability ...