Preview Tool

Cisco Bug: CSCus46861 - LIZRD attack : Denial of Service

Last Modified

Nov 19, 2018

Products (1)

  • Cisco 5500 Series Wireless Controllers

Known Affected Releases

7.4(121.0) 8.0(100.0)

Description (partial)

A vulnerability in the wireless intrusion detection (WIDS) feature of the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, remote attacker to force the WLC to become unresponsive.

This vulnerability was found and reported to Cisco by Darren Johnson.

For a Cisco WLC with a default configuration, the attacker could exploit this vulnerability by sending a large number of crafted packets to an affected WLC. The attack requires an administrator to click the IDS events under Security > Wireless Protection Policies > Signature Events Summary in the WLC admin web interface. When the administrator clicks the IDS events after the attacker sends the crafted packets, the WLC becomes unresponsive and all wireless clients are disconnected.

The attack has no effect, unless the web page is specifically opened by administrator
Bug details contain sensitive information and therefore require a account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.