Vulnerability Name:

CVE-2007-4012 (CCN-44591)

Assigned:2007-07-24
Published:2007-07-24
Updated:2018-10-30
Summary:Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software 4.1 before 4.1.180.0 allows remote attackers to cause a denial of service (ARP storm) via a broadcast ARP packet that "targets the IP address of a known client context", aka CSCsj50374.
CVSS v3 Severity:7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C)
5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2007-4012

Source: CCN
Type: SA26161
Cisco Multiple Products Wireless ARP Requests Denial of Service

Source: SECUNIA
Type: Vendor Advisory
26161

Source: CCN
Type: SECTRACK ID: 1018444
Cisco Wireless LAN Controller ARP Processing Lets Remote Users Deny Service

Source: CISCO
Type: UNKNOWN
20070724 Wireless ARP Storm Vulnerability

Source: CCN
Type: cisco-sa-20070724-arp
Cisco Security Advisory: Wireless ARP Storm Vulnerabilities

Source: CCN
Type: OSVDB ID: 36661
Cisco Multiple Products Wireless LAN Controller (WLC) Broadcast ARP Storm Remote DoS

Source: BID
Type: UNKNOWN
25043

Source: CCN
Type: BID-25043
Cisco Wireless LAN Control ARP Storm Multiple Denial Of Service Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1018444

Source: VUPEN
Type: UNKNOWN
ADV-2007-2636

Source: XF
Type: UNKNOWN
cisco-wlc-arp-dos(35576)

Source: XF
Type: UNKNOWN
cisco-wlc-broadcast-arp-dos(44591)

Source: XF
Type: UNKNOWN
cisco-wlc-broadcast-arp-dos(44591)

Vulnerable Configuration:Configuration 1:
  • cpe:/h:cisco:4100_wireless_lan_controller:*:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:4400_wireless_lan_controller:*:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:airespace_4000_wireless_lan_controller:*:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:catalyst_3750:*:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:catalyst_6500:*:*:*:*:*:*:*:*
  • AND
  • cpe:/o:cisco:wireless_lan_controller_software:3.2:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:wireless_lan_controller_software:3.2.116.21:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:wireless_lan_controller_software:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:wireless_lan_controller_software:4.0.155.0:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:wireless_lan_controller_software:4.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:cisco:wireless_lan_controller:3.2.116.21:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:wireless_lan_controller:4.0.155.0:*:*:*:*:*:*:*
  • AND
  • cpe:/h:cisco:catalyst:6500:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:catalyst_3750:*:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:4400_wireless_lan_controller:*:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:4100_wireless_lan_controller:*:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:airespace_4000_wireless_lan_controller:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    cisco 4100 wireless lan controller *
    cisco 4400 wireless lan controller *
    cisco airespace 4000 wireless lan controller *
    cisco catalyst 3750 *
    cisco catalyst 6500 *
    cisco wireless lan controller software 3.2
    cisco wireless lan controller software 3.2.116.21
    cisco wireless lan controller software 4.0
    cisco wireless lan controller software 4.0.155.0
    cisco wireless lan controller software 4.1
    cisco wireless lan controller 3.2.116.21
    cisco wireless lan controller 4.0.155.0
    cisco catalyst 6500
    cisco catalyst 3750 *
    cisco 4400 wireless lan controller *
    cisco 4100 wireless lan controller *
    cisco airespace 4000 wireless lan controller *