CVE-2009-0059
Last modified
CVE-2009-0059 is a vulnerability of currently unknown severity. The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow remote attackers to cause a denial of service (device reload) via a web authentication (aka WebAuth) session that includes a malformed POST request to login.html.. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow remote attackers to cause a denial of service (device reload) via a web authentication (aka WebAuth) session that includes a malformed POST request to login.html.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | 4400 Wireless Lan Controller | 4.1 |
| Cisco | 4400 Wireless Lan Controller | 4.2 |
| Cisco | 4400 Wireless Lan Controller | 5.2 |
| Cisco | Catalyst 3750 Series Integrated Wireless Lan Controller | 4.1 |
| Cisco | Catalyst 3750 Series Integrated Wireless Lan Controller | 4.2 |
| Cisco | Catalyst 3750 Series Integrated Wireless Lan Controller | 5.2 |
| Cisco | Catalyst 6500 Series Integrated Wireless Lan Controller | 4.1 |
| Cisco | Catalyst 6500 Series Integrated Wireless Lan Controller | 4.2 |
| Cisco | Catalyst 6500 Series Integrated Wireless Lan Controller | 5.2 |
| Cisco | Catalyst 7600 Series Wireless Lan Controller | 4.1 |
| Cisco | Catalyst 7600 Series Wireless Lan Controller | 4.2 |
| Cisco | Catalyst 7600 Series Wireless Lan Controller | 5.2 |
| Cisco | Wireless Lan Controller Software | 4.1 |
| Cisco | Wireless Lan Controller Software | 4.2 |
| Cisco | Wireless Lan Controller Software | 5.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0059?
How severe is CVE-2009-0059?
How do I fix CVE-2009-0059?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0053PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 …
- CVE-2009-0054PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 …
- CVE-2009-0055Cross-site request forgery (CSRF) vulnerability in the admin…
- CVE-2009-0056Cross-site request forgery (CSRF) vulnerability in the admin…
- CVE-2009-0057The Certificate Authority Proxy Function (CAPF) service in C…
- CVE-2009-0058The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500…
- CVE-2009-0061Unspecified vulnerability in the Wireless LAN Controller (WL…
- CVE-2009-0062Unspecified vulnerability in the Cisco Wireless LAN Controll…
- CVE-2009-0063Cross-site scripting (XSS) vulnerability in the Control Cent…
- CVE-2009-0064Multiple unspecified vulnerabilities in the Control Center i…
- CVE-2009-0065Buffer overflow in net/sctp/sm_statefuns.c in the Stream Con…
- CVE-2009-0066Multiple unspecified vulnerabilities in Intel system softwar…
Are you affected by CVE-2009-0059?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
