First published: Thu Mar 06 2014(Updated: )
Cisco Wireless LAN Controller (WLC) devices 7.0 before 7.0.250.0, 7.2, 7.3, and 7.4 before 7.4.110.0 do not properly deallocate memory, which allows remote attackers to cause a denial of service (reboot) by sending WebAuth login requests at a high rate, aka Bug ID CSCuf52361.
Credit: ykramarz@cisco.com psirt@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Wireless LAN Controller software 7.1 | =7.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.0.220.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.0.235.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.2 | |
Cisco Wireless LAN Controller software 7.1 | =7.2.103.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.2.110.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.3 | |
Cisco Wireless LAN Controller software 7.1 | =7.3.101.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.4.100.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.4.100.60 | |
Cisco Wireless LAN Controller software | <=- | |
All of | ||
Any of | ||
Cisco Wireless LAN Controller software 7.1 | =7.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.0.220.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.0.235.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.2 | |
Cisco Wireless LAN Controller software 7.1 | =7.2.103.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.2.110.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.3 | |
Cisco Wireless LAN Controller software 7.1 | =7.3.101.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.4.100.0 | |
Cisco Wireless LAN Controller software 7.1 | =7.4.100.60 | |
Cisco Wireless LAN Controller software | <=- |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0701 has a medium severity rating, as it can lead to a denial of service on affected Cisco Wireless LAN Controllers.
To fix CVE-2014-0701, update your Cisco Wireless LAN Controller software to version 7.0.250.0 or later for 7.0 branches and 7.4.110.0 or later for 7.4 branches.
CVE-2014-0701 affects Cisco Wireless LAN Controller devices running versions prior to 7.0.250.0, 7.2, 7.3, and 7.4 before 7.4.110.0.
CVE-2014-0701 can be exploited by remote attackers sending excessive WebAuth login requests to cause a denial of service.
Currently, there are no published workarounds for CVE-2014-0701, and the recommended solution is to upgrade the software.