Vulnerability identifier: #VU15412
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0443
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The weakness exists in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software due to improper input validation on fields within CAPWAP Discovery Request packets. A remote attacker can cause the Cisco WLC Software to disconnect associated access points (APs).
Affected software
Cisco Wireless LAN Controller
How to mitigate CVE-2018-0443
The vulnerability has been addressed in the versions 8.7(102.0), 8.7(1.14), 8.6(101.0), 8.6(1.103), 8.5(110.0), 8.5(107.59), 8.3(140.0), 8.3(134.67), 8.2(170.0), 8.2(167.207), 8.2(167.8), 8.0(154.2).
Cisco Wireless LAN Controller - addressed in versions 8.0.154.2, 8.2.167.8, 8.3.134.22, 8.3.140.0, 8.5.107.61, 8.5.110.0, 8.6.1.130, 8.6.101.0, 8.7.1.42, 8.7.102.0
External References
Related Security Bulletins