安全研究

安全漏洞
Cisco Wireless LAN Controller HTTP请求拒绝服务漏洞(CVE-2012-0368)

发布日期:2012-02-29
更新日期:2012-02-29

受影响系统:
Cisco Wireless LAN Controller 7.2
Cisco Wireless LAN Controller 7.1
Cisco Wireless LAN Controller 7.0
Cisco Wireless LAN Controller 6.0
Cisco Wireless LAN Controller 5.2
Cisco Wireless LAN Controller 5.1
Cisco Wireless LAN Controller 5.0
Cisco Wireless LAN Controller 4.2 M
Cisco Wireless LAN Controller 4.2
Cisco Wireless LAN Controller 4.1 M
Cisco Wireless LAN Controller 4.1
Cisco Wireless LAN Controller 4.0
不受影响系统:
Cisco Wireless LAN Controller 7.2.103.0
Cisco Wireless LAN Controller 7.1.91.0
Cisco Wireless LAN Controller 7.0.220.0
描述:
BUGTRAQ  ID: 52212
CVE ID: CVE-2012-0368

Cisco WLC 负责全系统的无线LAN功能,例如安全策略、入侵保护、RF管理,服务质量和移动性。

Cisco WLC在实现上存在远程拒绝服务漏洞,未验证的攻击者可提交畸形URL到管理界面,利用此漏洞造成受影响设备重载,拒绝服务合法用户。此漏洞其Cisco Bug ID CSCts81997。

<*来源:Cisco
  
  链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-wlc
*>

建议:
厂商补丁:

Cisco
-----
Cisco已经为此发布了一个安全公告(cisco-sa-20120229-wlc)以及相应补丁:

cisco-sa-20120229-wlc:Multiple Vulnerabilities in Cisco Wireless LAN Controllers

链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-wlc

浏览次数:2068
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障