CVE-2016-9194

moderate-risk
Published 2017-04-06

A vulnerability in 802.11 Wireless Multimedia Extensions (WME) action frame processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of the 802.11 WME packet header. An attacker could exploit this vulnerability by sending malformed 802.11 WME frames to a targeted device. A successful exploit could allow the attacker to cause the WLC to reload unexpectedly. The fixed versions are 8.0.140.0, 8.2.130.0, and 8.3.111.0. Cisco Bug IDs: CSCva86353.

Do I need to act?

-
0.18% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.5/10 Medium
ADJACENT_NETWORK / LOW complexity

Affected Products (20)

Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller
Wireless Lan Controller 6.0
Wireless Lan Controller 6.0
Wireless Lan Controller 7.0

Affected Vendors

48
/ 100
moderate-risk
Severity 21/34 · High
Exploitability 1/34 · Minimal
Exposure 26/34 · High