CVE-2016-6376
The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device…
Does this matter?
Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.
Description
The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device restart) via a malformed wIPS packet, aka Bug ID CSCuz40263.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- cisco/wireless lan controller · cisco/wireless lan controller 6.0 · cisco/wireless lan controller 7.0 · cisco/wireless lan controller 7.1 · cisco/wireless lan controller 7.2 · cisco/wireless lan controller 7.4
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-wlc-2Vendor Advisory
- http://www.securityfocus.com/bid/92716
- http://www.securitytracker.com/id/1036720
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-wlc-2Vendor Advisory
- http://www.securityfocus.com/bid/92716
- http://www.securitytracker.com/id/1036720
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.