CVE-2009-0059

UnknownEPSS 1.93%

Last modified

CVE-2009-0059 is a vulnerability of currently unknown severity. The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow remote attackers to cause a denial of service (device reload) via a web authentication (aka WebAuth) session that includes a malformed POST request to login.html.. EPSS estimates a 1.93% chance of exploitation in the next 30 days.

Description

The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow remote attackers to cause a denial of service (device reload) via a web authentication (aka WebAuth) session that includes a malformed POST request to login.html.

Metrics

EPSS Probability
1.93%

77.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Cisco4400 Wireless Lan Controller4.1
Cisco4400 Wireless Lan Controller4.2
Cisco4400 Wireless Lan Controller5.2
CiscoCatalyst 3750 Series Integrated Wireless Lan Controller4.1
CiscoCatalyst 3750 Series Integrated Wireless Lan Controller4.2
CiscoCatalyst 3750 Series Integrated Wireless Lan Controller5.2
CiscoCatalyst 6500 Series Integrated Wireless Lan Controller4.1
CiscoCatalyst 6500 Series Integrated Wireless Lan Controller4.2
CiscoCatalyst 6500 Series Integrated Wireless Lan Controller5.2
CiscoCatalyst 7600 Series Wireless Lan Controller4.1
CiscoCatalyst 7600 Series Wireless Lan Controller4.2
CiscoCatalyst 7600 Series Wireless Lan Controller5.2
CiscoWireless Lan Controller Software4.1
CiscoWireless Lan Controller Software4.2
CiscoWireless Lan Controller Software5.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-0059?
The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow remote attackers to cause a denial of service (device reload) via a web authentication (aka WebAuth) session that includes a malformed POST request to login.html.
How severe is CVE-2009-0059?
Severity scoring for CVE-2009-0059 is pending analysis. The EPSS model estimates a 1.93% probability of exploitation in the next 30 days.
How do I fix CVE-2009-0059?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-0059?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST