First published: Mon Apr 16 2007(Updated: )
The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.193.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug ID CSCsg36361.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco 2000 Wireless LAN Controller | ||
Cisco 2100 Wireless LAN Controller | ||
Cisco 4100 Wireless LAN Controller | ||
Cisco 4400 Wireless Lan Controller |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2038 is classified as a high severity vulnerability due to its potential for remote denial of service attacks.
To fix CVE-2007-2038, upgrade the Cisco Wireless LAN Controller to a version that is not affected, such as 3.2.193.5 or later for 3.2.x series.
CVE-2007-2038 affects Cisco 2000, 2100, 4100, and 4400 Wireless LAN Controllers running affected versions.
Yes, CVE-2007-2038 can be exploited by remote attackers on the same local wireless network.
The CVE-2007-2038 vulnerability can be triggered by crafted SNAP packets and malformed 802.11 traffic.