CVE-2007-2039
The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted…
Does this matter?
Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.
Description
The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug IDs CSCsg15901 and CSCsh10841.
- CVSS 2.0
- 6.1 MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- cisco/wireless lan controller software
- Source
- cve@mitre.org
References
- http://securitytracker.com/id?1017908Third Party Advisory, VDB Entry
- http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtmlPatch, Vendor Advisory
- http://www.osvdb.org/34137Broken Link
- http://www.osvdb.org/34139Broken Link
- http://www.securityfocus.com/bid/23461Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/1368Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33609Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1017908Third Party Advisory, VDB Entry
- http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtmlPatch, Vendor Advisory
- http://www.osvdb.org/34137Broken Link
- http://www.osvdb.org/34139Broken Link
- http://www.securityfocus.com/bid/23461Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/1368Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33609Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.