SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-2038

The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.193.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted…

MEDIUM 6.1EPSS 0.98%

Does this matter?

Lower severity and a low EPSS score (0.98%). Track it; it rarely justifies an emergency change on its own.

Description

The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.193.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug ID CSCsg36361.

CVSS 2.0
6.1 MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
EPSS
0.98% probability · 60th percentile
CISA KEV
Not listed
Affected
cisco/2000 wireless lan controller · cisco/2100 wireless lan controller · cisco/4100 wireless lan controller · cisco/4400 wireless lan controller
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.