CVE-2017-3832
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a missing internal handler for the specific request. An attacker could exploit this vulnerability by accessing a specific hidden URL on the GUI web management interface. A successful exploit could allow the attacker to cause a reload of the device, resulting in a DoS condition. This vulnerability affects only the Cisco Wireless LAN Controller 8.3.102.0 release. Cisco Bug IDs: CSCvb48198.
Una vulnerabilidad en la interfaz de administración web del software Cisco Wireless LAN Controller (WLC) podría permitir a un atacante remoto no autenticado provocar una condición de denegación de servicio (DoS) en un dispositivo afectado. La vulnerabilidad se debe a que falta un controlador interno para la solicitud específica. Un atacante podría explotar esta vulnerabilidad accediendo a una URL oculta específica en la interfaz de administración web de la GUI. Una explotación exitosa podría permitir al atacante provocar una recarga del dispositivo, resultando en una condición DoS. Esta vulnerabilidad sólo afecta a la versión de Cisco Wireless LAN Controller 8.3.102.0. Cisco Bug IDs: CSCvb48198.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-21 CVE Reserved
- 2017-04-06 CVE Published
- 2024-08-05 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
- CWE-755: Improper Handling of Exceptional Conditions
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/97421 | Third Party Advisory | |
http://www.securitytracker.com/id/1038184 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-wlc3 | 2021-11-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Wireless Lan Controller Firmware Search vendor "Cisco" for product "Wireless Lan Controller Firmware" | 8.3.102.0 Search vendor "Cisco" for product "Wireless Lan Controller Firmware" and version "8.3.102.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Wireless Lan Controller Search vendor "Cisco" for product "Wireless Lan Controller" | - | - |
Safe
|