CVE-2016-9194 describes a denial-of-service vulnerability in Cisco Wireless LAN Controller (WLC) Software affecting versions 6.0 through 7.4. This flaw stems from incomplete input validation of 802.11 Wireless Multimedia Extensions (WME) packet headers. An unauthenticated, adjacent attacker can exploit this by sending malformed WME frames, causing the WLC to unexpectedly reload. With a CVSS score of 6.5 (Medium), the attack requires adjacent network access but has low complexity and no user interaction, leading to high availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2.157.0CPE matchmatch criteria | cpe:2.3:a:cisco:wireless_lan_controller:5.2.157.0:*:*:*:*:*:*:* | ||
5.2.169.0CPE matchmatch criteria | cpe:2.3:a:cisco:wireless_lan_controller:5.2.169.0:*:*:*:*:*:*:* | ||
6.0_baseCPE matchmatch criteria | cpe:2.3:a:cisco:wireless_lan_controller:6.0_base:*:*:*:*:*:*:* | ||
7.0_baseCPE matchmatch criteria | cpe:2.3:a:cisco:wireless_lan_controller:7.0_base:*:*:*:*:*:*:* | ||
7.1_baseCPE matchmatch criteria | cpe:2.3:a:cisco:wireless_lan_controller:7.1_base:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.