CVE-2013-1235
Last modified
CVE-2013-1235 is a vulnerability of currently unknown severity. Cisco Wireless LAN Controller (WLC) devices do not properly address the resource consumption of terminated TELNET sessions, which allows remote attackers to cause a denial of service (TELNET outage) by making many TELNET connections and improperly ending these connections, aka Bug ID CSCug35507.. EPSS estimates a 1.23% chance of exploitation in the next 30 days.
Description
Cisco Wireless LAN Controller (WLC) devices do not properly address the resource consumption of terminated TELNET sessions, which allows remote attackers to cause a denial of service (TELNET outage) by making many TELNET connections and improperly ending these connections, aka Bug ID CSCug35507.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | 2000 Wireless Lan Controller | All versions |
| Cisco | 2100 Wireless Lan Controller | All versions |
| Cisco | 2106 Wireless Lan Controller | All versions |
| Cisco | 2112 Wireless Lan Controller | All versions |
| Cisco | 2125 Wireless Lan Controller | All versions |
| Cisco | 2500 Wireless Lan Controller | All versions |
| Cisco | 2504 Wireless Lan Controller | All versions |
| Cisco | 4100 Wireless Lan Controller | All versions |
| Cisco | 4400 Wireless Lan Controller | All versions |
| Cisco | 4402 Wireless Lan Controller | All versions |
| Cisco | 4404 Wireless Lan Controller | All versions |
| Cisco | 5500 Wireless Lan Controller | All versions |
| Cisco | 7500 Wireless Lan Controller | All versions |
| Cisco | 8500 Wireless Lan Controller | All versions |
| Cisco | Airespace 4000 Wireless Lan Controller | All versions |
| Cisco | Wireless Lan Controller | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-1235?
How severe is CVE-2013-1235?
How do I fix CVE-2013-1235?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-1229TMSSNMPService.exe in TelePresence Manager in Cisco TelePres…
- CVE-2013-1230Cisco Unified Communications Domain Manager allows remote at…
- CVE-2013-1231The HTTP implementation in Cisco WebEx Node for MCS and WebE…
- CVE-2013-1232The HTTP implementation in Cisco WebEx Node for MCS, WebEx M…
- CVE-2013-1233Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-1234The SNMP module in Cisco IOS XR allows remote authenticated …
- CVE-2013-1236Cisco TelePresence Supervisor MSE 8050 before 2.3(1.31) allo…
- CVE-2013-1240The command-line interface in Cisco Unified Communications M…
- CVE-2013-1241The ISM module in Cisco IOS on ISR G2 routers does not prope…
- CVE-2013-1242Memory leak in the web framework in the server in Cisco Unif…
- CVE-2013-1243The IP stack in Cisco Intrusion Prevention System (IPS) Soft…
- CVE-2013-1244Cross-site scripting (XSS) vulnerability in the portal modul…
Are you affected by CVE-2013-1235?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
