Cisco patches Denial of Service vulnerabilities in wireless LAN Controllers

Cisco WLAN
Cisco gets the plasters out for its WLC range

Cisco has patched a number of vulnerabilities in its Wireless LAN Controller (WLC) family of products, including several bugs that allowed denial of service attacks.

Six vulnerabilities have been fixed in the update, including a denial of service security hole in the WebAuth feature of WLCs that allowed unauthenticated remote attackers to cause a device to reload. This could be replicated repeatedly to consume all memory on a device and leave it essentially unusable.

Four more WLC denial of service vulnerabilities received a plaster, including an IGMP processing subsystem weakness, an MLD service bug, a critical error hole, and a controller crafted frame vulnerability.

Another bug in the Cisco IOS code that allowed unauthorised access to associated access points in Cisco Aironet 1260, 2600, 3500, and 3600 Series devices by Cisco WLCs was also addressed.

Vulnerable devices

Admins can mitigate the associated access point issue by configuring Global AP Management Credentials on their devices. There are no workarounds for the denial of service vulnerabilities.

Affected devices include the Cisco 500 Series Wireless Express Mobility Controllers, the Cisco 2000, 2100, 4100, and 4400 Wireless LAN Controllers, the Cisco 2500, 5500, and 8500 Wireless Controllers, and the Cisco Flex 7500 Series and Virtual Wireless Controllers.

Additional modular controllers affected include the Cisco Catalyst 6500 Series and 7600 Series, the Wireless Services Module version 2, the NME-AIR WLC and NM-AIR-WLC Modules for Integrated Services Routers, the Catalyst 3750G Integrated WLC, and the Wireless Controller Software for Services-Ready Engine.

Cisco urged customers to check with their maintenance providers before deploying the patch in case of any compatibility issues.

Via The Register

Latest in Pro
Epson EcoTank ET-4850 next to a TechRadar badge that reads Big Savings
I found the best printer deal you won't see in the Amazon Spring Sale and it's got a massive $150 saving
NVIDIA RTX PRO 6000 Blackwell Server Edition
Nvidia's most expensive Blackwell card gets massive price cut but it is not the RTX 5090
Microsoft Copiot Studio deep reasoning and agent flows
Microsoft reveals OpenAI-powered Copilot AI agents to bosot your work research and data analysis
Group of people meeting
Inflexible work policies are pushing tech workers to quit
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
Latest in News
Hisense U8 series TV on wall in living room
Hisense announces 2025 mini-LED TV lineup, with screen sizes up to 100 inches – and a surprising smart TV switch
Nintendo Music teaser art
Nintendo Music expands its library with songs from Kirby and the Forgotten Land and Tetris
Opera AI Tabs
Opera's new AI feature brings order to your browser tab chaos
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode