cisco wireless-lan-controller CVE-2019-1799 vulnerability in Cisco Products
Published on April 18, 2019

Cisco Wireless LAN Controller Software IAPP Message Handling Denial of Service Vulnerabilities
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit the vulnerability by sending malicious IAPP messages to an affected device. A successful exploit could allow the attacker to cause the Cisco WLC Software to reload, resulting in a DoS condition. Software versions prior to 8.2.170.0, 8.5.150.0, and 8.8.100.0 are affected.

Vendor Advisory NVD

Weakness Type

Resource Management Errors

Weaknesses in this category are related to improper management of system resources.


Products Associated with CVE-2019-1799

stack.watch emails you whenever new vulnerabilities are published in Cisco Wireless Lan Controller or Cisco Wireless Lan Controller Software. Just hit a watch button to start following.

 
 

Affected Versions

Cisco Wireless LAN Controller (WLC):

Exploit Probability

EPSS
0.15%
Percentile
34.92%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.