First published: Thu Jul 26 2007(Updated: )
Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software 4.1 before 4.1.180.0 allows remote attackers to cause a denial of service (ARP storm) via a broadcast ARP packet that "targets the IP address of a known client context", aka CSCsj50374.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco 4100 Wireless LAN Controller | ||
Cisco 4400 Wireless LAN Controller | ||
Cisco Airespace 4000 Wireless LAN Controller | ||
Cisco Catalyst 3750 Series | ||
Cisco Catalyst 6500-E | ||
Cisco Wireless LAN Controller software 7.1 | =3.2 | |
Cisco Wireless LAN Controller software 7.1 | =3.2.116.21 | |
Cisco Wireless LAN Controller software 7.1 | =4.0 | |
Cisco Wireless LAN Controller software 7.1 | =4.0.155.0 | |
Cisco Wireless LAN Controller software 7.1 | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4012 is classified as a high severity vulnerability due to its potential to cause a denial of service.
To mitigate CVE-2007-4012, upgrade the Wireless LAN Controller software to version 4.1.180.0 or later.
CVE-2007-4012 affects Cisco 4100 and 4400 Wireless LAN Controllers, Airespace 4000, and Catalyst 6500 and 3750 with specific software versions.
Yes, CVE-2007-4012 can be exploited remotely by sending a broadcast ARP packet targeting a known client IP.
CVE-2007-4012 allows remote attackers to create an ARP storm, leading to a denial of service on Cisco Wireless LAN Controllers.