VendorsCiscowireless_lan_controller_softwareall versions
Vulnerabilities

Cisco Wireless

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

88CVEs
CVE-2018-0388
Cisco Wireless LAN Controller Software Cross-Site Scripting Vulnerability
Published 2018-10-17 · Modified
4.8EPSS 0.010
CVE-2018-0247
A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic. The vulnerability is due to incorrect implementation of authentication for WebAuth clients in a specific configuration. An attacker could exploit this vulnerability by sending traffic to local network resources without having gone through authentication. A successful exploit could allow the attacker to bypass authentication and pass traffic. This affects Cisco Aironet Access Points running Cisco IOS Software and Cisco Wireless LAN Controller (WLC) releases prior to 8.5.110.0 for the following specific WLC configuration only: (1) The Access Point (AP) is configured in FlexConnect Mode with NAT. (2) The WLAN is configured for central switching, meaning the client is being assigned a unique IP address. (3) The AP is configured with a Split Tunnel access control list (ACL) for access to local network resources, meaning the AP is doing the NAT on the connection. (4) The client is using WebAuth. This vulnerability does not apply to .1x clients in the same configuration. Cisco Bug IDs: CSCvc79502, CSCvf71789.
Published 2018-05-02 · Modified
4.7EPSS 0.009
CVE-2023-20268
Cisco Access Point Software Uncontrolled Resource Consumption Vulnerability
Published 2023-09-27 · Modified
4.7EPSS 0.002
CVE-2019-15266
Cisco Wireless LAN Controller Path Traversal Vulnerability
Published 2019-10-16 · Modified
4.4EPSS 0.007
CVE-2021-1423
Cisco Aironet Access Points Arbitrary File Overwrite Vulnerability
Published 2021-03-24 · Modified
4.4EPSS 0.002
CVE-2012-6007
Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID CSCud65187, a different vulnerability than CVE-2012-5992.
Published 2012-12-19 · Modified
4.31 PoCEPSS 0.037
CVE-2015-0690
Cross-site scripting (XSS) vulnerability in the HTML help system on Cisco Wireless LAN Controller (WLC) devices before 8.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCun95178.
Published 2015-04-07 · Modified
4.3EPSS 0.009
CVE-2007-2037
Cisco Wireless LAN Controller (WLC) before 3.2.116.21, and 4.0.x before 4.0.155.0, allows remote attackers on a local network to cause a denial of service (device crash) via malformed Ethernet traffic.
Published 2007-04-16 · Modified
2.9EPSS 0.009
← Prev3 / 3