ID

VAR-E-200907-1149


CVE

cve_id:CVE-2009-1164

Trust: 0.3

sources: BID: 35805

TITLE

Cisco Wireless LAN Controller HTTP Authorization Denial of Service Vulnerability

Trust: 0.3

sources: BID: 35805

DESCRIPTION

Cisco Wireless LAN Controller is prone to a denial-of-service vulnerability when handling specially crafted HTTP requests.
An attacker can exploit this issue to trigger an affected device to reboot, causing denial-of-service conditions.
This issue affects Cisco Wireless LAN Controller 4402 (software release 5.1.151.0); other versions and devices may be affected as well.

Trust: 0.3

sources: BID: 35805

AFFECTED PRODUCTS

vendor:ciscomodel:wireless lan controllerscope:eqversion:44000

Trust: 0.6

vendor:ciscomodel:wireless lan controllerscope:eqversion:21000

Trust: 0.6

vendor:ciscomodel:wlc modules for integrated services routersscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:wireless services modulesscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:wireless lan controlscope:eqversion:5.2

Trust: 0.3

vendor:ciscomodel:wireless lan controlscope:eqversion:5.1

Trust: 0.3

vendor:ciscomodel:wireless lan controlscope:eqversion:5.0

Trust: 0.3

vendor:ciscomodel:wireless lan control mscope:eqversion:4.2

Trust: 0.3

vendor:ciscomodel:wireless lan controlscope:eqversion:4.2

Trust: 0.3

vendor:ciscomodel:catalyst 3750gscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:eqversion:55000

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:eqversion:44040

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:eqversion:44020

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:eqversion:42000

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:eqversion:41000

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:eqversion:21060

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:eqversion:20060

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:eqversion:20000

Trust: 0.3

vendor:ciscomodel: - scope:eqversion:1500

Trust: 0.3

vendor:ciscomodel:wireless lan controlscope:neversion:6.0.182.0

Trust: 0.3

vendor:ciscomodel:wireless lan controlscope:neversion:5.2.193.0

Trust: 0.3

vendor:ciscomodel:wireless lan controlscope:neversion:4.2.207.0

Trust: 0.3

sources: BID: 35805

EXPLOIT

Attackers can use readily available network utilities or a browser to exploit this issue.
The following exploit is available:
Bullet list:
<li><a href="/data/vulnerabilities/exploits/35805.rb">/data/vulnerabilities/exploits/35805.rb</a></li>

Trust: 0.3

sources: BID: 35805

PRICE

Free

Trust: 0.3

sources: BID: 35805

TYPE

Failure to Handle Exceptional Conditions

Trust: 0.3

sources: BID: 35805

CREDITS

Christoph Bott

Trust: 0.3

sources: BID: 35805

EXTERNAL IDS

db:NVDid:CVE-2009-1164

Trust: 0.3

db:BIDid:35805

Trust: 0.3

sources: BID: 35805

REFERENCES

url:http://www.cisco.com/

Trust: 0.3

url:http://www.cisco.com/warp/public/707/cisco-sa-20090727-wlc.shtml

Trust: 0.3

sources: BID: 35805

SOURCES

db:BIDid:35805

LAST UPDATE DATE

2022-07-27T09:59:32.133000+00:00


SOURCES UPDATE DATE

db:BIDid:35805date:2009-07-27T18:05:00

SOURCES RELEASE DATE

db:BIDid:35805date:2009-07-26T00:00:00