CVE-2013-1102
The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.0, 7.1 and 7.2 before 7.2.110.0, and 7.3 before 7.3.101.0 allows remote attackers to cause a denial of service…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.82%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.0, 7.1 and 7.2 before 7.2.110.0, and 7.3 before 7.3.101.0 allows remote attackers to cause a denial of service (device reload) via crafted IP packets, aka Bug ID CSCtx80743.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 1.82% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- cisco/wireless lan controller software · cisco/2000 wireless lan controller · cisco/2100 wireless lan controller · cisco/2500 wireless lan controller · cisco/4100 wireless lan controller · cisco/4400 wireless lan controller · cisco/5500 wireless lan controller · cisco/7500 wireless lan controller · cisco/8500 wireless lan controller
- Source
- psirt@cisco.com
References
- http://secunia.com/advisories/51965
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130123-wlcVendor Advisory
- http://www.securityfocus.com/bid/57524
- http://www.securitytracker.com/id/1028027
- http://secunia.com/advisories/51965
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130123-wlcVendor Advisory
- http://www.securityfocus.com/bid/57524
- http://www.securitytracker.com/id/1028027
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.