Vulnerability record · CVE-2019-15276 · published 26 November 2019
CVE-2019-15276: Cisco Wireless LAN Controller web interface URL parsing DoS
Cisco · Wireless Lan Controller Software
Cisco Wireless LAN Controller Software fails to properly validate specially crafted URLs in its web interface HTTP parsing engine. A low-privileged authenticated remote attacker, or an unauthenticated attacker who convinces a logged-in user to click a crafted URL, can trigger an unexpected device restart. The result is a denial of service on the controller, which can disrupt managed wireless access.
Description
A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTTP parsing engine to handle specially crafted URLs. An attacker could exploit this vulnerability by authenticating with low privileges to an affected controller and submitting the crafted URL to the web interface of the affected device. Conversely, an unauthenticated attacker could exploit this vulnerability by persuading a user of the web interface to click the crafted URL. A successful exploit could allow the attacker to cause an unexpected restart of the device, resulting in a DoS condition.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw causes full availability loss on a network-critical controller, a public exploit reference exists, and EPSS is high despite the medium CVSS score and no KEV listing.
What it is
Cisco Wireless LAN Controller Software fails to properly validate specially crafted URLs in its web interface HTTP parsing engine. A low-privileged authenticated remote attacker, or an unauthenticated attacker who convinces a logged-in user to click a crafted URL, can trigger an unexpected device restart. The result is a denial of service on the controller, which can disrupt managed wireless access.
Impact
An attacker can force an unexpected restart of the affected controller, causing a denial of service and loss of wireless management or connectivity for dependent access points and clients. No confidentiality or integrity impact is described; the effect is availability only.
Attack surface
Reachable over the network through the controller web interface. Exploitation requires either low-privileged authentication or, for an unauthenticated attacker, user interaction in the form of a victim clicking a crafted URL.
Exploitation
Not listed in CISA KEV, but a public exploit reference exists (Packet Storm advisory tagged Exploit) and EPSS is high at roughly 0.46 probability (98.8th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the Cisco security advisory cisco-sa-20191106-wlc-dos fix for affected Wireless LAN Controller Software versions.
- Restrict web interface access to trusted management networks and disable it where not required.
- Enforce least privilege so few accounts hold even low-privileged web access.
- Filter or block malformed and suspicious URL patterns at the management boundary.
- Monitor controller restarts and correlate them with web interface access logs.
Detection
- Alert on unexpected controller restarts or reboots and correlate with web interface sessions.
- Review web interface access logs for malformed or unusually crafted URL requests.
- Monitor for low-privileged accounts submitting anomalous HTTP requests to the controller.
- Track authentication events followed closely by device restart or availability loss.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/155554/Cisco-WLC-2504-8.9-Denial-Of-Service.html | ExploitThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-wlc-dos | Vendor Advisory |
| http://packetstormsecurity.com/files/155554/Cisco-WLC-2504-8.9-Denial-Of-Service.html | ExploitThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-wlc-dos | Vendor Advisory |
Track CVE-2019-15276 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-15276), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.