CVE-2012-0368: High severity cisco wireless lan controller software 7.1 vulnerability
The administrative management interface on Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allows remote attackers to cause a denial of service (device crash) via a malformed URL in an HTTP request, aka Bug ID CSCts81997.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0368?
CVE-2012-0368 has a medium severity rating as it allows remote attackers to cause a denial of service by crashing Cisco Wireless LAN Controller devices.
How do I fix CVE-2012-0368?
To fix CVE-2012-0368, update your Cisco Wireless LAN Controller software to versions 7.0.220.0 or later, 7.1.91.0 or later, or 7.2.103.0 or later.
Which Cisco Wireless LAN Controller versions are affected by CVE-2012-0368?
CVE-2012-0368 affects Cisco Wireless LAN Controller software versions 4.x, 5.x, 6.0, and 7.0 prior to 7.0.220.0.
Can a malformed URL in an HTTP request trigger CVE-2012-0368?
Yes, CVE-2012-0368 can be triggered by sending a malformed URL in an HTTP request to the vulnerable Cisco Wireless LAN Controller.
What impact does CVE-2012-0368 have on Cisco Wireless LAN Controllers?
The impact of CVE-2012-0368 is a denial of service, resulting in a device crash of affected Cisco Wireless LAN Controller devices.