ID

VAR-201510-0019


CVE

CVE-2015-6341


TITLE

Cisco Wireless LAN Controller Runs on device software Web Management GUI Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2015-005604

DESCRIPTION

The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a denial of service (client disconnection) via unspecified vectors, aka Bug ID CSCuw10610. Vendors have confirmed this vulnerability Bug ID CSCuw10610 It is released as.Service disruption by a third party ( Disconnecting clients ) There is a possibility of being put into a state. Attackers can exploit this issue to cause a denial-of-service condition. This issue is being tracked by Cisco Bug ID CSCuw10610. This product provides functions such as security policy and intrusion detection in wireless LAN. A remote attacker could exploit this vulnerability to cause a denial of service (client disconnection)

Trust: 1.98

sources: NVD: CVE-2015-6341 // JVNDB: JVNDB-2015-005604 // BID: 77119 // VULHUB: VHN-84302

AFFECTED PRODUCTS

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.4.140.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.0.120.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.4(140.0)

Trust: 0.8

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.0(120.0)

Trust: 0.8

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.0(120)

Trust: 0.3

sources: BID: 77119 // JVNDB: JVNDB-2015-005604 // CNNVD: CNNVD-201510-572 // NVD: CVE-2015-6341

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-6341
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-6341
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201510-572
value: MEDIUM

Trust: 0.6

VULHUB: VHN-84302
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-6341
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-84302
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-84302 // JVNDB: JVNDB-2015-005604 // CNNVD: CNNVD-201510-572 // NVD: CVE-2015-6341

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-84302 // JVNDB: JVNDB-2015-005604 // NVD: CVE-2015-6341

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201510-572

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201510-572

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-005604

PATCH

title:cisco-sa-20151016-wlcurl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151016-wlc

Trust: 0.8

sources: JVNDB: JVNDB-2015-005604

EXTERNAL IDS

db:NVDid:CVE-2015-6341

Trust: 2.8

db:SECTRACKid:1033871

Trust: 1.1

db:JVNDBid:JVNDB-2015-005604

Trust: 0.8

db:CNNVDid:CNNVD-201510-572

Trust: 0.7

db:BIDid:77119

Trust: 0.4

db:VULHUBid:VHN-84302

Trust: 0.1

sources: VULHUB: VHN-84302 // BID: 77119 // JVNDB: JVNDB-2015-005604 // CNNVD: CNNVD-201510-572 // NVD: CVE-2015-6341

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20151016-wlc

Trust: 2.0

url:http://www.securitytracker.com/id/1033871

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-6341

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-6341

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:http://www.cisco.com/c/en/us/support/wireless/wireless-lan-controller-software/tsd-products-support-series-home.html

Trust: 0.3

sources: VULHUB: VHN-84302 // BID: 77119 // JVNDB: JVNDB-2015-005604 // CNNVD: CNNVD-201510-572 // NVD: CVE-2015-6341

CREDITS

Cisco

Trust: 0.3

sources: BID: 77119

SOURCES

db:VULHUBid:VHN-84302
db:BIDid:77119
db:JVNDBid:JVNDB-2015-005604
db:CNNVDid:CNNVD-201510-572
db:NVDid:CVE-2015-6341

LAST UPDATE DATE

2024-11-23T23:12:37.720000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-84302date:2017-01-05T00:00:00
db:BIDid:77119date:2015-10-16T00:00:00
db:JVNDBid:JVNDB-2015-005604date:2015-10-28T00:00:00
db:CNNVDid:CNNVD-201510-572date:2015-10-26T00:00:00
db:NVDid:CVE-2015-6341date:2024-11-21T02:34:49.167

SOURCES RELEASE DATE

db:VULHUBid:VHN-84302date:2015-10-25T00:00:00
db:BIDid:77119date:2015-10-16T00:00:00
db:JVNDBid:JVNDB-2015-005604date:2015-10-28T00:00:00
db:CNNVDid:CNNVD-201510-572date:2015-10-26T00:00:00
db:NVDid:CVE-2015-6341date:2015-10-25T02:59:11.480