CVE-2017-3832: High severity Cisco Wireless Lan Controller Firmware vulnerability
A vulnerability in the web management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a missing internal handler for the specific request. An attacker could exploit this vulnerability by accessing a specific hidden URL on the GUI web management interface. A successful exploit could allow the attacker to cause a reload of the device, resulting in a DoS condition. This vulnerability affects only the Cisco Wireless LAN Controller 8.3.102.0 release. Cisco Bug IDs: CSCvb48198.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the DoS by restricting or blocking access to the Cisco WLC web management GUI on the network (since the attacker exploits a specific hidden URL on the GUI).
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3832?
CVE-2017-3832 is classified as a high severity vulnerability due to its potential to allow an unauthenticated remote attacker to cause a denial of service on affected devices.
How do I fix CVE-2017-3832?
To resolve CVE-2017-3832, upgrade to a fixed version of Cisco Wireless LAN Controller software as specified in Cisco’s security advisory.
What are the affected versions in CVE-2017-3832?
The affected version for CVE-2017-3832 is Cisco Wireless LAN Controller firmware version 8.3.102.0.
Is a workaround available for CVE-2017-3832?
There are no specific workarounds available for CVE-2017-3832; the recommended action is to upgrade the software.
Can CVE-2017-3832 be exploited remotely?
Yes, CVE-2017-3832 can be exploited remotely by an unauthenticated attacker to achieve a denial of service condition.