SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-0368

The administrative management interface on Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allows remote attackers to cause a denial of service (device…

HIGH 7.8EPSS 1.32%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The administrative management interface on Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allows remote attackers to cause a denial of service (device crash) via a malformed URL in an HTTP request, aka Bug ID CSCts81997.

CVSS 2.0
7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS
1.32% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-399
Affected
cisco/wireless lan controller software · cisco/2000 wireless lan controller · cisco/2100 wireless lan controller · cisco/2106 wireless lan controller · cisco/2112 wireless lan controller · cisco/2125 wireless lan controller · cisco/2500 wireless lan controller · cisco/2504 wireless lan controller · cisco/4100 wireless lan controller · cisco/4400 wireless lan controller · cisco/4402 wireless lan controller · cisco/4404 wireless lan controller · cisco/5508 wireless controller
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.