ID

VAR-201609-0353


CVE

CVE-2016-6375


TITLE

Cisco Wireless LAN Controller Service disruption on devices (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2016-004632

DESCRIPTION

Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow remote attackers to cause a denial of service (device reload) by sending crafted Inter-Access Point Protocol (IAPP) packets and then sending a traffic stream metrics (TSM) information request over SNMP, aka Bug ID CSCuz40221. Cisco Wireless LAN Controller (WLC) Device has a service disruption ( Device reload ) There are vulnerabilities that are put into a state. An unauthenticated attacker with a physical location approaching the vulnerability to restart the WLC unexpectedly can cause a denial of service. Attackers can exploit this issue to restart the affected device, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCuz40221. A denial of service vulnerability exists in Cisco WLC versions 8.0.140, 8.2.121.0, and 8.3.102.0

Trust: 2.52

sources: NVD: CVE-2016-6375 // JVNDB: JVNDB-2016-004632 // CNVD: CNVD-2016-07020 // BID: 92712 // VULHUB: VHN-95195

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-07020

AFFECTED PRODUCTS

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.155.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.1.105.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.182.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.1_base

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.108

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.206.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.2.150.6

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.196

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.2.78.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.2.185.0

Trust: 1.6

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.0_base

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 7.0scope:eqversion:116.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.1.59.24

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.217.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.0.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 7.0scope:eqversion:252.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.3.112

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.6.110.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 6.0scope:eqversion:196.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.6.120.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.6.130.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.4.1.1

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.0.100

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.179.11

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.1.171.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.61.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.0.148.2

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.3.101.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.1.185.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.3_base

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.112.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.4.121.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.4.100

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.1.111.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 6.0scope:eqversion:199.4

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.130.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 7.1scope:eqversion:91.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.173.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.0.72.140

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.2.157.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.2.171.5

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 7.0scope:eqversion:250.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.0.120.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 7.0scope:eqversion:220.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 7.4scope:eqversion:1.54

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.1.104.37

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.0.148.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.155.5

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.0_base

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.1.130.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 7.4scope:eqversion:1.19

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2_base

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.4.100.60

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 7.0scope:eqversion:240.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.5.102.11

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.176.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.4_base

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.99.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.1.181.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.1.151.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.219.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.117.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.2.193.5

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 6.0scope:eqversion:202.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.0.0.30220.385

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.1.111.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.6.1.62

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.2.150.10

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.3.103.8

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 7.2scope:eqversion:103.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:6.0_base

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.0.121.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.1.122.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.0.179.8

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.2.169.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.4.110.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.5_base

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 7.4scope:eqversion:140.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:4.2.174.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 6.0scope:eqversion:182.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.2.195.10

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 7.0scope:eqversion:98.218

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.6.100.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.2.116.21

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.2.171.6

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.1.160.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.1_base

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.1.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 7.0scope:eqversion:98.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:3.6.0e

Trust: 1.0

vendor:ciscomodel:wireless lan controller software 6.0scope:eqversion:188.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.5.102.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.0.115.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:5.1.152.0

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:7.2_base

Trust: 1.0

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.3.102.0

Trust: 0.8

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.2.121.0

Trust: 0.8

vendor:ciscomodel:wireless lan controller softwarescope:ltversion:8.3.x

Trust: 0.8

vendor:ciscomodel:wireless lan controller softwarescope:ltversion:8.2.x

Trust: 0.8

vendor:ciscomodel:wireless lan controller softwarescope:eqversion:8.1.x

Trust: 0.8

vendor:ciscomodel:wireless lan controllerscope:eqversion:8.0.140

Trust: 0.6

vendor:ciscomodel:wireless lan controllerscope:eqversion:8.2.121.0

Trust: 0.6

vendor:ciscomodel:wireless lan controllerscope:eqversion:8.3.102.0

Trust: 0.6

vendor:ciscomodel:wireless lan controllerscope:eqversion:8.3

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:eqversion:8.2

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:eqversion:8.0.121.0

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:eqversion:8.0.120.0

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:eqversion:8.0.100.0

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:neversion:8.0.140

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:neversion:8.3.102.0

Trust: 0.3

vendor:ciscomodel:wireless lan controllerscope:neversion:8.2.121.0

Trust: 0.3

sources: CNVD: CNVD-2016-07020 // BID: 92712 // JVNDB: JVNDB-2016-004632 // CNNVD: CNNVD-201608-534 // NVD: CVE-2016-6375

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-6375
value: MEDIUM

Trust: 1.0

NVD: CVE-2016-6375
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2016-07020
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201608-534
value: MEDIUM

Trust: 0.6

VULHUB: VHN-95195
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2016-6375
severity: MEDIUM
baseScore: 5.7
vectorString: AV:A/AC:M/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2016-07020
severity: MEDIUM
baseScore: 5.7
vectorString: AV:A/AC:M/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-95195
severity: MEDIUM
baseScore: 5.7
vectorString: AV:A/AC:M/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-6375
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 1.6
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2016-07020 // VULHUB: VHN-95195 // JVNDB: JVNDB-2016-004632 // CNNVD: CNNVD-201608-534 // NVD: CVE-2016-6375

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

sources: VULHUB: VHN-95195 // JVNDB: JVNDB-2016-004632 // NVD: CVE-2016-6375

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201608-534

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201608-534

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-004632

PATCH

title:cisco-sa-20160831-wlc-1url:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-wlc-1

Trust: 0.8

title:Patch for CiscoWirelessLANControllerTSMSNMP Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/80992

Trust: 0.6

title:Cisco Wireless LAN Controller Remediation measures for denial of service vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=63831

Trust: 0.6

sources: CNVD: CNVD-2016-07020 // JVNDB: JVNDB-2016-004632 // CNNVD: CNNVD-201608-534

EXTERNAL IDS

db:NVDid:CVE-2016-6375

Trust: 3.4

db:BIDid:92712

Trust: 2.0

db:SECTRACKid:1036721

Trust: 1.1

db:JVNDBid:JVNDB-2016-004632

Trust: 0.8

db:CNNVDid:CNNVD-201608-534

Trust: 0.7

db:CNVDid:CNVD-2016-07020

Trust: 0.6

db:NSFOCUSid:34700

Trust: 0.6

db:VULHUBid:VHN-95195

Trust: 0.1

sources: CNVD: CNVD-2016-07020 // VULHUB: VHN-95195 // BID: 92712 // JVNDB: JVNDB-2016-004632 // CNNVD: CNNVD-201608-534 // NVD: CVE-2016-6375

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20160831-wlc-1

Trust: 2.6

url:http://www.securityfocus.com/bid/92712

Trust: 1.7

url:http://www.securitytracker.com/id/1036721

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-6375

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-6375

Trust: 0.8

url:http://www.nsfocus.net/vulndb/34700

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

url:http://www.cisco.com/en/us/products/ps6302/products_sub_category_home.html

Trust: 0.3

sources: CNVD: CNVD-2016-07020 // VULHUB: VHN-95195 // BID: 92712 // JVNDB: JVNDB-2016-004632 // CNNVD: CNNVD-201608-534 // NVD: CVE-2016-6375

CREDITS

Cisco

Trust: 0.9

sources: BID: 92712 // CNNVD: CNNVD-201608-534

SOURCES

db:CNVDid:CNVD-2016-07020
db:VULHUBid:VHN-95195
db:BIDid:92712
db:JVNDBid:JVNDB-2016-004632
db:CNNVDid:CNNVD-201608-534
db:NVDid:CVE-2016-6375

LAST UPDATE DATE

2024-11-23T23:09:11.445000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-07020date:2016-09-01T00:00:00
db:VULHUBid:VHN-95195date:2018-10-30T00:00:00
db:BIDid:92712date:2016-08-31T00:00:00
db:JVNDBid:JVNDB-2016-004632date:2016-09-14T00:00:00
db:CNNVDid:CNNVD-201608-534date:2016-09-13T00:00:00
db:NVDid:CVE-2016-6375date:2024-11-21T02:56:00.477

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-07020date:2016-09-01T00:00:00
db:VULHUBid:VHN-95195date:2016-09-12T00:00:00
db:BIDid:92712date:2016-08-31T00:00:00
db:JVNDBid:JVNDB-2016-004632date:2016-09-14T00:00:00
db:CNNVDid:CNNVD-201608-534date:2016-08-31T00:00:00
db:NVDid:CVE-2016-6375date:2016-09-12T01:59:01.130