Release date:
Updated on:
Affected Systems:
Cisco Wireless LAN Control 7.2
Cisco Wireless LAN Control 7.1
Cisco Wireless LAN Control 7.0
Unaffected system:
Cisco Wireless LAN Control 7.2.103.0
Cisco Wireless LAN Control 7.1.91.0
Cisco Wireless LAN Control 7.0.220.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57524
CVE (CAN) ID: CVE-2013-1103
Cisco WLC is responsible for system-wide wireless LAN functions, such as security policies, intrusion protection, RF management, service quality and mobility.
Cisco Wireless Access Points (AP) managed by the Cisco Wireless LAN Controller does not properly filter specially crafted SIP packets, allowing unauthenticated remote attackers to cause DoS on the AP device.
<* Source: Cisco
Link: http://seclists.org/fulldisclosure/2013/Jan/208
Http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130123-wlc
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20130123-wlc) and patches for this:
Cisco-sa-20130123-wlc: Multiple Vulnerabilities in Cisco Wireless LAN Controllers
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130123-wlc