You are here
Home > Preporuke > Ranjivost Cisco Wireless LAN Controller (WLC) softvera

Ranjivost Cisco Wireless LAN Controller (WLC) softvera

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: CIS

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

Cisco Security Advisory: Cisco Wireless LAN Controller Simple Network Management Protocol Memory Leak Denial of Service Vulnerability

Advisory ID: cisco-sa-20171101-wlc1

Revision: 1.0

For Public Release: 2017 November 1 16:00 GMT

Last Updated: 2017 November 1 16:00 GMT

CVE ID(s): CVE-2017-12278

CVSS Score v(3): 7.7 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

+———————————————————————

Summary
=======
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Wireless LAN Controllers could allow an authenticated, remote attacker to cause an affected device to restart, resulting in a denial of service (DoS) condition.

The vulnerability is due to a memory leak that occurs on an affected device after the device fails to deallocate a buffer that is used when certain MIBs are polled. An attacker who knows the SNMP Version 2 SNMP Read string or has valid SNMP Version 3 credentials for an affected device could repeatedly poll the affected MIB object IDs (OIDs) and consume available memory on the device. When memory is sufficiently depleted on the device, the device will restart, resulting in a DoS condition.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171101-wlc1 [“https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171101-wlc1”]

—–BEGIN PGP SIGNATURE—–

iQKBBAEBAgBrBQJZ+fHgZBxDaXNjbyBTeXN0ZW1zIFByb2R1Y3QgU2VjdXJpdHkg
SW5jaWRlbnQgUmVzcG9uc2UgVGVhbSAoQ2lzY28gUFNJUlQga2V5IDIwMTYtMjAx
NykgPHBzaXJ0QGNpc2NvLmNvbT4ACgkQrz2APcQAkHmHng//SAZJp8OYZLywITU0
+pDgKpqLC93001+MrblT8/g0naWzF+W+M5kaDJ9zDRDTnYezKWNIyNQqrIgQ099d
7CZyzH8oDVf14qQUTubSXr8Ms7BCTJvqcYf1Ml7rERcd0fiwAj11789BHRtMMFVr
QG9InX255PjyHZMDl6fyPtoBfbSXuaDy6yfV1k0zx0suSGDjo6ive4Pflpk/Hy58
mqJMH9DhXyiEG1ipiqMGB/GbtfW0/A7lI6hydUR9ks4J4oqvrszVB+tBUsaqeiZn
os5yFWmy7YxqCqNDdzBXA+Gz83FEDPi56+REzYEsrYMTjJfAAhV+4v51EzcpBgnc
hV3e1yzcxZ+uhpoFZDaAPUvCEIsk2qLDeqzZwol6GgXEwCwagMvmrjNSm/RJT8qv
1dRC/lRZAALtRipCtC6ufabBZbgXbzYFTLs1QjJSp7pbxFW+8S4q6Cr7KuWEDO36
5eubeB5taXSI8LJieXGUhYGRBMFxvlBwcOUEL6UwCMi8MCn8shD9LYPX9smsfXLw
nnEv8stzKD+C9yKHBOnD7gvoV2VOEHZjEhmH5Yp/Gae5ruI2YoyQuSXq3e3BTBvW
k77W5CS+en/NnlRT9tM4EYlOBYEPf/zuNusnof2B17d4hjjkE/aPzdkebVFFKeTA
yXgIRWFUg/bgIBQtLzL2aMBjnA4=
=GTn4
—–END PGP SIGNATURE—–

_______________________________________________
cust-security-announce mailing list
cust-security-announce@cisco.com
To unsubscribe, send the command “unsubscribe” in the subject of your message to cust-security-announce-leave@cisco.com

AutorVlatka Misic
Cert idNCERT-REF-2017-11-0024-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Ranjivost Cisco Wireless LAN Controller (WLC) softvera

Otkrivena je ranjivost u 802.11v Basic Service Set (BSS) Transition Management funkcionalnosti u Cisco Wireless LAN Controller (WLC) softveru, a...

Close