ID

VAR-201403-0208


CVE

CVE-2014-0704


TITLE

Cisco Wireless LAN Controller Device IGMP Service disruption in implementations (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-001582

DESCRIPTION

The IGMP implementation on Cisco Wireless LAN Controller (WLC) devices 4.x, 5.x, 6.x, 7.0 before 7.0.250.0, 7.1, 7.2, and 7.3, when IGMPv3 Snooping is enabled, allows remote attackers to cause a denial of service (memory over-read and device restart) via a crafted field in an IGMPv3 message, aka Bug ID CSCuh33240. A security vulnerability exists in the Cisco Wireless LAN Controller IGMP processing subsystem. The attacker can inject malicious IGMPv3 messages into the network monitored by the WLC because the specific fields in the specially crafted IGMP message type are not properly verified. The IGMP subsystem can process messages. Triggering memory out-of-bounds reads can overload the device and cause a denial of service attack. This issue is being tracked by Cisco Bug ID CSCuh33240. The vulnerability is caused by the program not validating special fields in the IGMP message type. The following versions are affected: Cisco Wireless LAN Controller (WLC) 4.x, 5.x, 6.x, 7.0 prior to 7.0.250.0, 7.1, 7.2, 7.3

Trust: 2.52

sources: NVD: CVE-2014-0704 // JVNDB: JVNDB-2014-001582 // CNVD: CNVD-2014-01544 // BID: 65980 // VULHUB: VHN-68197

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-01544

AFFECTED PRODUCTS

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.3

Trust: 2.4

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.2

Trust: 2.4

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.1

Trust: 2.4

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.0.220.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.0.98.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.3.101.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.0.235.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.2.103.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.2.110.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.1.91.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.176.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.182.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.217.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.99.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.1

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:6.0.196.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.1.181.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.1.151.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.1

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.219.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.117.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:6.0.199.4

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.179.11

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.1.171.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.1m

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.61.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.0.148.2

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.1.185.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.2

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.112.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.2.169.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.179.8

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.174.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.130.0

Trust: 1.0

vendor:ciscomodel:wireless lan controllerscope:eqversion:*

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.206.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.173.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.2.157.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2m

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.155.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:6.0.182.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.108

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.1.160.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.196

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:6.0.199.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.0.148.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.155.5

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:6.0.188.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:6.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.1.152.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.0

Trust: 1.0

vendor:ciscomodel:wireless lan controllerscope: - version: -

Trust: 0.8

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.0.250.0

Trust: 0.8

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.x

Trust: 0.8

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:6.x

Trust: 0.8

vendor:ciscomodel:wireless lan controller softwarescope:ltversion:7.0

Trust: 0.8

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.x

Trust: 0.8

vendor:ciscomodel:wireless lan controllerscope:eqversion:7.2

Trust: 0.6

vendor:ciscomodel:wireless lan controllerscope:eqversion:7.3

Trust: 0.6

vendor:ciscomodel:wireless lan controllerscope:eqversion:7.4

Trust: 0.6

vendor:ciscomodel:wireless lan controllerscope:eqversion:4.x

Trust: 0.6

vendor:ciscomodel:wireless lan controllerscope:eqversion:5.x

Trust: 0.6

vendor:ciscomodel:wireless lan controllerscope:eqversion:6.x

Trust: 0.6

vendor:ciscomodel:wireless lan controllerscope:eqversion:7.5

Trust: 0.6

sources: CNVD: CNVD-2014-01544 // JVNDB: JVNDB-2014-001582 // CNNVD: CNNVD-201403-135 // NVD: CVE-2014-0704

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-0704
value: HIGH

Trust: 1.0

NVD: CVE-2014-0704
value: HIGH

Trust: 0.8

CNVD: CNVD-2014-01544
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201403-135
value: HIGH

Trust: 0.6

VULHUB: VHN-68197
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-0704
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-01544
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-68197
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-01544 // VULHUB: VHN-68197 // JVNDB: JVNDB-2014-001582 // CNNVD: CNNVD-201403-135 // NVD: CVE-2014-0704

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

sources: VULHUB: VHN-68197 // JVNDB: JVNDB-2014-001582 // NVD: CVE-2014-0704

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201403-135

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201403-135

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001582

PATCH

title:30830url:http://tools.cisco.com/security/center/viewAMBAlert.x?alertId=30830

Trust: 0.8

title:cisco-sa-20140305-wlcurl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140305-wlc

Trust: 0.8

title:33100url:http://tools.cisco.com/security/center/viewAlert.x?alertId=33100

Trust: 0.8

title:cisco-sa-20140305-wlcurl:http://www.cisco.com/cisco/web/support/JP/112/1122/1122122_cisco-sa-20140305-wlc-j.html

Trust: 0.8

title:Patch for Cisco Wireless LAN Controller IGMP Remote Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/44140

Trust: 0.6

sources: CNVD: CNVD-2014-01544 // JVNDB: JVNDB-2014-001582

EXTERNAL IDS

db:NVDid:CVE-2014-0704

Trust: 3.4

db:BIDid:65980

Trust: 1.0

db:JVNDBid:JVNDB-2014-001582

Trust: 0.8

db:CNNVDid:CNNVD-201403-135

Trust: 0.7

db:CNVDid:CNVD-2014-01544

Trust: 0.6

db:SECUNIAid:57128

Trust: 0.6

db:CISCOid:20140305 MULTIPLE VULNERABILITIES IN CISCO WIRELESS LAN CONTROLLERS

Trust: 0.6

db:SEEBUGid:SSVID-61725

Trust: 0.1

db:VULHUBid:VHN-68197

Trust: 0.1

sources: CNVD: CNVD-2014-01544 // VULHUB: VHN-68197 // BID: 65980 // JVNDB: JVNDB-2014-001582 // CNNVD: CNNVD-201403-135 // NVD: CVE-2014-0704

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20140305-wlc

Trust: 2.3

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-0704

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-0704

Trust: 0.8

url:http://secunia.com/advisories/57128

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2014-01544 // VULHUB: VHN-68197 // BID: 65980 // JVNDB: JVNDB-2014-001582 // CNNVD: CNNVD-201403-135 // NVD: CVE-2014-0704

CREDITS

Cisco

Trust: 0.3

sources: BID: 65980

SOURCES

db:CNVDid:CNVD-2014-01544
db:VULHUBid:VHN-68197
db:BIDid:65980
db:JVNDBid:JVNDB-2014-001582
db:CNNVDid:CNNVD-201403-135
db:NVDid:CVE-2014-0704

LAST UPDATE DATE

2024-11-23T22:02:13.682000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-01544date:2014-03-11T00:00:00
db:VULHUBid:VHN-68197date:2014-03-07T00:00:00
db:BIDid:65980date:2014-03-05T00:00:00
db:JVNDBid:JVNDB-2014-001582date:2014-03-07T00:00:00
db:CNNVDid:CNNVD-201403-135date:2014-03-11T00:00:00
db:NVDid:CVE-2014-0704date:2024-11-21T02:02:40.210

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-01544date:2014-03-11T00:00:00
db:VULHUBid:VHN-68197date:2014-03-06T00:00:00
db:BIDid:65980date:2014-03-05T00:00:00
db:JVNDBid:JVNDB-2014-001582date:2014-03-07T00:00:00
db:CNNVDid:CNNVD-201403-135date:2014-03-11T00:00:00
db:NVDid:CVE-2014-0704date:2014-03-06T11:55:05.367