Home/Product/cisco wireless lan controller software
Product

cisco wireless lan controller software

88 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-20354
>= 8.5.171.0 and < 8.6.0.0
A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenti
4.7MEDIUM
CVE-2024-20271
< 8.10.190.0
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to
8.6HIGH
CVE-2023-20268
< 8.10.190.0
A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacen
4.7MEDIUM
CVE-2023-20097
< 8.10.183.0
A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and
4.6MEDIUM
CVE-2023-20056
< 8.10.183.0
A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a
6.5MEDIUM
CVE-2022-20769
< 8.10.171.0
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthen
7.4HIGH
CVE-2021-1419
>= 8.10 and < 8.10.151.0
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated u
7.8HIGH
CVE-2021-1423
< 8.5.171.0
A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local att
4.4MEDIUM
CVE-2021-1449
< 8.5.171.0
A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned
6.7MEDIUM
CVE-2021-1437
>= 8.10.112.0 and < 8.10.142.0
A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated,
7.5HIGH
CVE-2020-3560
< 8.5.161.0
A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service
8.6HIGH
CVE-2019-15276
>= 8.4 and < 8.10
A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote
6.5MEDIUM
CVE-2019-15266
< 8.10
A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view sy
4.4MEDIUM
CVE-2019-1830
< 8.3.150.0
A vulnerability in Locally Significant Certificate (LSC) management for the Cisco Wireless LAN Controller (WLC) could allow an aut
4.9MEDIUM
CVE-2019-1805
all versions
A vulnerability in certain access control mechanisms for the Secure Shell (SSH) server implementation for Cisco Wireless LAN Contr
4.3MEDIUM
CVE-2019-1800
>= 8.3 and < 8.5.150.0
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software cou
6.5MEDIUM
CVE-2019-1799
>= 8.3.143.0 and < 8.3.150.0
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software cou
6.5MEDIUM
CVE-2019-1797
< 8.3.150.0
A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticat
8.8HIGH
CVE-2019-1796
>= 8.3.143.0 and < 8.5.150.0
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software cou
6.5MEDIUM
CVE-2018-0382
all versions
A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller
5.3MEDIUM
CVE-2018-0248
< 8.3.150.0
A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could allow an aUT
6.8MEDIUM
CVE-2018-0443
all versions
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Contro
7.5HIGH
CVE-2018-0442
< 8.2.170.0
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Contro
7.5HIGH
CVE-2018-0420
all versions
A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an authenticated, remote attacker
6.5MEDIUM
CVE-2018-0417
< 8.2.170.0
A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local att
7.8HIGH
CVE-2018-15395
all versions
A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could
5.4MEDIUM
CVE-2018-0416
all versions
A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote
5.3MEDIUM
CVE-2018-0388
all versions
A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, remote at
4.8MEDIUM
CVE-2018-0252
all versions
A vulnerability in the IP Version 4 (IPv4) fragment reassembly function of Cisco 3500, 5500, and 8500 Series Wireless LAN Controll
8.6HIGH
CVE-2018-0247
all versions
A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points runn
4.7MEDIUM
CVE-2018-0245
all versions
A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticate
5.3MEDIUM
CVE-2018-0235
all versions
A vulnerability in the 802.11 frame validation functionality of the Cisco Wireless LAN Controller (WLC) could allow an unauthentic
7.4HIGH
CVE-2017-12282
all versions
A vulnerability in the Access Network Query Protocol (ANQP) ingress frame processing functionality of Cisco Wireless LAN Controlle
6.1MEDIUM
CVE-2017-12280
all versions
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) Discovery Request parsing functionality of Cisc
7.5HIGH
CVE-2017-12278
all versions
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Wireless LAN Controllers could allow an authen
6.3MEDIUM
CVE-2017-12275
all versions
A vulnerability in the implementation of 802.11v Basic Service Set (BSS) Transition Management functionality in Cisco Wireless LAN
7.4HIGH
CVE-2016-9219
all versions
A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthentic
7.5HIGH
CVE-2017-3854
all versions
A vulnerability in the mesh code of Cisco Wireless LAN Controller (WLC) software could allow an unauthenticated, remote attacker t
8.8HIGH
CVE-2016-6375
all versions
Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow r
5.3MEDIUM
CVE-2016-1460
all versions
Cisco Wireless LAN Controller (WLC) devices 7.4(121.0) and 8.0(0.30220.385) allow remote attackers to cause a denial of service vi
6.5MEDIUM
CVE-2016-1364
all versions
Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8.0.110.0(ED) allows remote att
7.5HIGH
CVE-2016-1363
>= 7.2.0 and < 7.4.140.0
Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(
9.8CRITICAL
CVE-2015-6314
all versions
Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attac
9.8CRITICAL
CVE-2015-6341
all versions
The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attack
CVE-2015-6302
all versions
The RADIUS functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.0(250.0) and 7.0(252.0) allows remote atta
CVE-2015-6258
all versions
The Internet Access Point Protocol (IAPP) module on Cisco Wireless LAN Controller (WLC) devices with software 8.1(104.37) allows r
CVE-2015-4224
all versions
Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands in a privi
CVE-2015-4215
all versions
Cisco Wireless LAN Controller (WLC) devices with software 7.5(102.0) and 7.6(1.62) allow remote attackers to cause a denial of ser
CVE-2015-0726
all versions
The web administration interface on Cisco Wireless LAN Controller (WLC) devices before 7.0.241, 7.1.x through 7.4.x before 7.4.122
CVE-2015-0723
all versions
The wireless web-authentication subsystem on Cisco Wireless LAN Controller (WLC) devices 7.5.x and 7.6.x before 7.6.120 allows rem
CVE-2015-0690
<= 8.0.72.140
Cross-site scripting (XSS) vulnerability in the HTML help system on Cisco Wireless LAN Controller (WLC) devices before 8.0 allows
CVE-2015-0679
all versions
The web-authentication functionality on Cisco Wireless LAN Controller (WLC) devices 7.3(103.8) and 7.4(110.0) allows remote attack
CVE-2014-0707
all versions
Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a denial of service
CVE-2014-0706
all versions
Cisco Wireless LAN Controller (WLC) devices 7.2 before 7.2.115.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a
CVE-2014-0705
all versions
The multicast listener discovery (MLD) service on Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, 7.4 before 7.4.121.0, and
CVE-2014-0704
all versions
The IGMP implementation on Cisco Wireless LAN Controller (WLC) devices 4.x, 5.x, 6.x, 7.0 before 7.0.250.0, 7.1, 7.2, and 7.3, whe
CVE-2014-0703
all versions
Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the stat
CVE-2014-0701
all versions
Cisco Wireless LAN Controller (WLC) devices 7.0 before 7.0.250.0, 7.2, 7.3, and 7.4 before 7.4.110.0 do not properly deallocate me
CVE-2013-1141
<= 7.4.1.54
The mDNS snooping functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.4.1.54 and earlier does not properl
CVE-2013-1105
all versions
Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.3, 7.1 and 7.2 before 7.2.111.3, and 7.3 before 7.3.1
CVE-2013-1104
all versions
The HTTP Profiling functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.3.101.0 allows remote authenticate
CVE-2013-1103
all versions
Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allo
CVE-2013-1102
all versions
The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) devices with software 7.0 before
CVE-2012-6007
all versions
Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with
CVE-2012-5992
all versions
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0
CVE-2012-5991
all versions
screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticat
CVE-2012-0371
all versions
Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.4, when CPU-based ACLs are enabled
CVE-2012-0370
all versions
Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.0 and 7.1 before 7.1.91.0, when We
CVE-2012-0369
all versions
Cisco Wireless LAN Controller (WLC) devices with software 6.0 and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.10
CVE-2012-0368
all versions
The administrative management interface on Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before
CVE-2011-1613
all versions
Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 6.0 before 6.0.200.0, 7.0 before 7.0.98.216, and 7.0.1xx
CVE-2010-3034
all versions
Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs
CVE-2010-3033
all versions
Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended acces
CVE-2010-2843
all versions
Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended acces
CVE-2010-2842
all versions
Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended acces
CVE-2010-2841
all versions
Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 4.2 before 4.2.209.0; 4.2M before 4.2.207.54M; 5.0, 5.1,
CVE-2010-0575
all versions
Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs
CVE-2010-0574
all versions
Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 3.2 before 3.2.215.0; 4.1 and 4.2 before 4.2.205.0; 4.1M
CVE-2009-0062
all versions
Unspecified vulnerability in the Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cis
CVE-2009-0061
all versions
Unspecified vulnerability in the Wireless LAN Controller (WLC) TSEC driver in the Cisco 4400 WLC, Cisco Catalyst 6500 and 7600 Wir
CVE-2009-0059
all versions
The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated W
CVE-2009-0058
all versions
The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated W
CVE-2007-4012
all versions
Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software 4.1 before 4.1.180.0 allows
CVE-2007-4011
all versions
Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software before 3.2 20070727, 4.0 be
CVE-2007-2040
>= 3.2 and < 3.2.185.0
Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3.2.185.0, and 4.0.x before 4.0.206.0, have a hard-code
CVE-2007-2039
>= 3.2 and < 3.2.171.5
The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x a
CVE-2007-2037
>= 3.2 and < 3.2.116.21
Cisco Wireless LAN Controller (WLC) before 3.2.116.21, and 4.0.x before 4.0.155.0, allows remote attackers on a local network to c
CVE-2007-2036
all versions
The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, an
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin