First published: Thu Feb 28 2013(Updated: )
The mDNS snooping functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.4.1.54 and earlier does not properly manage buffers, which allows remote authenticated users to cause a denial of service (device reload) via crafted mDNS packets, aka Bug ID CSCue04153.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Wireless LAN Controllers | <=7.4.1.54 | |
Cisco Wireless LAN Controllers | =3.0 | |
Cisco Wireless LAN Controllers | =3.2 | |
Cisco Wireless LAN Controllers | =3.2.116.21 | |
Cisco Wireless LAN Controllers | =4.0 | |
Cisco Wireless LAN Controllers | =4.0.108 | |
Cisco Wireless LAN Controllers | =4.0.155.0 | |
Cisco Wireless LAN Controllers | =4.0.155.5 | |
Cisco Wireless LAN Controllers | =4.0.179.8 | |
Cisco Wireless LAN Controllers | =4.0.179.11 | |
Cisco Wireless LAN Controllers | =4.0.196 | |
Cisco Wireless LAN Controllers | =4.0.206.0 | |
Cisco Wireless LAN Controllers | =4.0.217.0 | |
Cisco Wireless LAN Controllers | =4.0.219.0 | |
Cisco Wireless LAN Controllers | =4.1 | |
Cisco Wireless LAN Controllers | =4.1.171.0 | |
Cisco Wireless LAN Controllers | =4.1.181.0 | |
Cisco Wireless LAN Controllers | =4.1.185.0 | |
Cisco Wireless LAN Controllers | =4.1m | |
Cisco Wireless LAN Controllers | =4.2 | |
Cisco Wireless LAN Controllers | =4.2.61.0 | |
Cisco Wireless LAN Controllers | =4.2.99.0 | |
Cisco Wireless LAN Controllers | =4.2.112.0 | |
Cisco Wireless LAN Controllers | =4.2.117.0 | |
Cisco Wireless LAN Controllers | =4.2.130.0 | |
Cisco Wireless LAN Controllers | =4.2.173.0 | |
Cisco Wireless LAN Controllers | =4.2.174.0 | |
Cisco Wireless LAN Controllers | =4.2.176.0 | |
Cisco Wireless LAN Controllers | =4.2.182.0 | |
Cisco Wireless LAN Controllers | =4.2m | |
Cisco Wireless LAN Controllers | =5.0 | |
Cisco Wireless LAN Controllers | =5.0.148.0 | |
Cisco Wireless LAN Controllers | =5.0.148.2 | |
Cisco Wireless LAN Controllers | =5.1 | |
Cisco Wireless LAN Controllers | =5.1.151.0 | |
Cisco Wireless LAN Controllers | =5.1.152.0 | |
Cisco Wireless LAN Controllers | =5.1.160.0 | |
Cisco Wireless LAN Controllers | =5.2 | |
Cisco Wireless LAN Controllers | =5.2.157.0 | |
Cisco Wireless LAN Controllers | =5.2.169.0 | |
Cisco Wireless LAN Controllers | =6.0 | |
Cisco Wireless LAN Controllers | =6.0.182.0 | |
Cisco Wireless LAN Controllers | =6.0.188.0 | |
Cisco Wireless LAN Controllers | =6.0.196.0 | |
Cisco Wireless LAN Controllers | =6.0.199.0 | |
Cisco Wireless LAN Controllers | =6.0.199.4 | |
Cisco Wireless LAN Controllers | =7.0 | |
Cisco Wireless LAN Controllers | =7.0.98.0 | |
Cisco Wireless LAN Controllers | =7.0.220.0 | |
Cisco Wireless LAN Controllers | =7.0.235.0 | |
Cisco Wireless LAN Controllers | =7.1 | |
Cisco Wireless LAN Controllers | =7.1.91.0 | |
Cisco Wireless LAN Controllers | =7.2 | |
Cisco Wireless LAN Controllers | =7.2.103.0 | |
Cisco Wireless LAN Controllers | =7.2.110.0 | |
Cisco Wireless LAN Controllers | =7.3 | |
Cisco Wireless LAN Controllers | =7.3.101.0 | |
Cisco Wireless LAN Controllers |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1141 has a high severity rating due to its potential to cause a denial of service by reloading affected devices.
To address CVE-2013-1141, update your Cisco Wireless LAN Controller software to version 7.4.1.55 or later.
CVE-2013-1141 affects Cisco Wireless LAN Controller versions 7.4.1.54 and earlier, along with multiple other specific versions listed in the advisory.
CVE-2013-1141 exploits a buffer management issue in the mDNS snooping functionality, allowing crafted mDNS packets to affect device stability.
CVE-2013-1141 can be exploited by remote authenticated users, making it crucial to limit access to trusted individuals only.