← Back

CVE-2016-9194

nvd nist
Published: Apr 6, 2017Modified: May 13, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in 802.11 Wireless Multimedia Extensions (WME) action frame processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of the 802.11 WME packet header. An attacker could exploit this vulnerability by sending malformed 802.11 WME frames to a targeted device. A successful exploit could allow the attacker to cause the WLC to reload unexpectedly. The fixed versions are 8.0.140.0, 8.2.130.0, and 8.3.111.0. Cisco Bug IDs: CSCva86353.

Affected (53)

6 products
Wireless Lan Controller
Wireless Lan Controller 6.0
Wireless Lan Controller 7.0
Wireless Lan Controller 7.1
Wireless Lan Controller 7.2
Wireless Lan Controller 7.4
Configuration A
53 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 5.2.157.0
Version 5.2.169.0
Version 6.0_base
Version 7.0_base
Version 7.1_base
Version 7.2_base
Version 7.3.101.0
Version 7.3.103.8
Version 7.3.112
Version 7.3_base
Version 7.4.1.1
Version 7.4.100.60
Version 7.4.100
Version 7.4.110.0
Version 7.4.121.0
Version 7.4_base
Version 7.5.102.0
Version 7.5.102.11
Version 7.5_base
Version 7.6.1.62
Version 7.6.100.0
Version 7.6.110.0
Version 7.6.120.0
Version 7.6.130.0
Version 8.0.0.30220.385
Version 8.0.0
Version 8.0.100
Version 8.0.115.0
Version 8.0.120.0
Version 8.0.121.0
Version 8.0.72.140
Version 8.1.0
Version 8.1.104.37
Version 8.1.111.0
Version 8.1.122.0
Version 8.1.130.0
Cisco
Version 182.0
Version 188.0
Version 196.0
Version 199.4
Version 202.0
Cisco
Version 116.0
Version 220.0
Version 240.0
Version 250.0
Version 252.0
Version 98.0
Version 98.218
Version 91.0
Version 103.0
Cisco
Version 1.19
Version 1.54
Version 140.0

Related CWEs

References (6)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.