CVE-2012-0371
Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.4, when CPU-based ACLs are enabled, allow remote attackers to read or modify the configuration via unspecified vectors, aka Bug ID CSCtu56709.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.4, when CPU-based ACLs are enabled, allow remote attackers to read or modify the configuration via unspecified vectors, aka Bug ID CSCtu56709.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/wireless lan controller software · cisco/2000 wireless lan controller · cisco/2100 wireless lan controller · cisco/2106 wireless lan controller · cisco/2112 wireless lan controller · cisco/2125 wireless lan controller · cisco/2500 wireless lan controller · cisco/2504 wireless lan controller · cisco/4100 wireless lan controller · cisco/4400 wireless lan controller · cisco/4402 wireless lan controller · cisco/4404 wireless lan controller · cisco/5508 wireless controller
- Source
- psirt@cisco.com
References
- http://archives.neohapsis.com/archives/bugtraq/2012-02/0188.html
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-wlcVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2012-02/0188.html
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-wlcVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.