CVE-2016-9219: Input Validation
A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an unexpected reload of the device. The vulnerability is due to incomplete IPv6 UDP header validation. An attacker could exploit this vulnerability by sending a crafted IPv6 UDP packet to a specific port on the targeted device. An exploit could allow the attacker to impact the availability of the device as it could unexpectedly reload. This vulnerability affects Cisco Wireless LAN Controller (WLC) running software version 8.2.121.0 or 8.3.102.0. Cisco Bug IDs: CSCva98592.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9219?
CVE-2016-9219 is rated as a high severity vulnerability due to its potential to allow an unauthenticated attacker to reload the device.
How do I fix CVE-2016-9219?
To mitigate CVE-2016-9219, upgrade the Cisco Wireless LAN Controller firmware to a fixed version that addresses this vulnerability.
What are the affected versions for CVE-2016-9219?
CVE-2016-9219 affects Cisco Wireless LAN Controller firmware versions 8.2.121.0 and 8.3.102.0.
Can CVE-2016-9219 be exploited remotely?
Yes, CVE-2016-9219 can be exploited remotely by an unauthenticated attacker via IPv6 UDP header issues.
What type of devices are affected by CVE-2016-9219?
CVE-2016-9219 affects Cisco Wireless LAN Controllers running specific vulnerable firmware versions.