peter bassill · operator
$ cve CVE-2016-1363 JSON

CVE-2016-1363

9.8
CRITICAL · CVSS 3.1 · EPSS 5.6% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through 8.0 before 8.0.115.0(ED) allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCus25617.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.58% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-399
On CISA KEVno
Public exploitnone known
Published2016-04-21
Last modified2026-06-17

Affected (1)

VendorProduct
ciscowireless lan controller software

References

→ the Explorer  ·  watch your stack  ·  NVD