Cisco Wireless LAN Controller DoS (CVE-2014-3291)
Release date:
Updated on:
Affected Systems:
Cisco Wireless LAN Controller
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67926
CVE (CAN) ID: CVE-2014-3291
Cisco WLC is responsible for system-wide wireless LAN functions, such as security policies, intrusion protection, RF management, service quality and mobility.
A security vulnerability exists in the Cisco Wireless LAN Controller device. Remote attackers fail to pass the zero value in the Cisco Discovery Protocol packet that is not correctly processed in SNMP polling, this vulnerability causes NULL pointer indirect reference and device restart, resulting in DOS.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3291
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.cisco.com/go/psirt
This article permanently updates the link address: