CVE-2013-3474: Buffer Overflow
The Web Administrator Interface on Cisco Wireless LAN Controller (WLC) devices allows remote authenticated users to cause a denial of service (device crash) by leveraging membership in the Full Manager managers group, Read Only managers group, or Lobby Ambassador managers group, and sending a request that (1) lacks a parameter value or (2) contains a malformed parameter value, aka Bug IDs CSCuh14313, CSCuh14159, CSCuh14368, and CSCuh14436.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3474?
CVE-2013-3474 is classified as a denial of service vulnerability affecting Cisco Wireless LAN Controllers.
How do I fix CVE-2013-3474?
To mitigate CVE-2013-3474, upgrade to the latest version of the Cisco Wireless LAN Controller software that addresses this vulnerability.
Who is affected by CVE-2013-3474?
Remote authenticated users with access to specific management groups can exploit CVE-2013-3474.
What does CVE-2013-3474 allow an attacker to do?
CVE-2013-3474 allows attackers to send requests that may crash the device, leading to a denial of service.
Is CVE-2013-3474 still relevant?
While CVE-2013-3474 was reported a while ago, its relevance depends on whether affected systems are still in use without proper patches.