CVE-2019-15276 is a denial-of-service vulnerability in the web interface of Cisco Wireless LAN Controller Software. It allows an authenticated, low-privileged attacker to crash the device by submitting a specially crafted URL, or an unauthenticated attacker to achieve the same by tricking a user into clicking a malicious link. With a CVSS score of 6.5 (Medium), the vulnerability has a network attack vector and low attack complexity, leading to a complete loss of availability. While not on the KEV catalog, a public Proof-of-Concept exploit (EDB-47744) exists, and it has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.4, < 8.10CPE matchmatch criteria | cpe:2.3:a:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.