Cisco Wireless LAN Controller broadcast ARP packet denial of service
| cisco-wlc-broadcast-arp-dos (44591) |
Description:
Multiple Cisco Wireless LAN Controllers are vulnerable to a denial of service. By sending a specially-crafted broadcast ARP packet to the context of a known client's IP address, a remote attacker could exploit this vulnerability to cause an ARP storm resulting in a denial of service.
Platforms Affected:
- Cisco, 4100 Wireless LAN Controller
- Cisco, 4400 Wireless LAN Controller
- Cisco, Airespace 4000 Wireless LAN Controller
- Cisco, Catalyst 3750
- Cisco, Catalyst 6500
- Cisco, Wireless LAN Controller 3.2
- Cisco, Wireless LAN Controller 3.2.116.21
- Cisco, Wireless LAN Controller 4.0
- Cisco, Wireless LAN Controller 4.0.155.0
- Cisco, Wireless LAN Controller 4.1
Remedy:
Refer to cisco-sa-20070724-arp for patch, upgrade, or suggested workaround information. See References.
Consequences:
Denial of Service
References:
- cisco-sa-20070724-arp, Cisco Security Advisory: Wireless ARP Storm Vulnerabilities at http://www.cisco.com/warp/public/707/cisco-sa-20070724-arp.shtml.
- BID-25043: Cisco Wireless LAN Control ARP Storm Multiple Denial Of Service Vulnerabilities
- CVE-2007-4012: Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software 4.1 before 4.1.180.0 allows remote attackers to cause a denial of service (ARP storm) via a broadcast ARP packet that targets the IP address of a known client context, aka CSCsj50374.
- SA26161: Cisco Multiple Products Wireless ARP Requests Denial of Service
- SECTRACK ID: 1018444: Cisco Wireless LAN Controller ARP Processing Lets Remote Users Deny Service
- VUPEN/ADV-2007-2636: Cisco Wireless LAN Controllers Address Resolution Protocol Denial of Service Issues
Reported:
Jul 24, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
