CVE-2019-1796 describes a denial-of-service vulnerability in Cisco Wireless LAN Controller (WLC) Software, affecting versions prior to 8.2.170.0, 8.5.150.0, and 8.8.100.0. The flaw stems from improper input validation of Inter-Access Point Protocol (IAPP) messages. An unauthenticated, adjacent attacker can exploit this by sending malicious IAPP messages, causing the WLC to reload and resulting in a denial-of-service condition. This vulnerability has a CVSS score of 6.5 (Medium), indicating a low attack complexity and no user interaction required, but it necessitates physical proximity to the network. While the potential impact is high availability loss, there is no compromise of confidentiality or integrity. Currently, there is no known active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB. The vulnerability has also garnered minimal community discussion or media coverage, suggesting a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.2.170.0CPE matchmatch criteria | cpe:2.3:a:cisco:wireless_lan_controller:*:*:*:*:*:*:*:* | ||
>= 8.3.143.0, < 8.5.150.0CPE matchmatch criteria | cpe:2.3:o:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:* | ||
>= 8.7.106.0, < 8.8.100.0CPE matchmatch criteria | cpe:2.3:o:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.