CVE-2016-9194: Cisco Wireless Lan Controller

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability in 802.11 Wireless Multimedia Extensions (WME) action frame processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of the 802.11 WME packet header. An attacker could exploit this vulnerability by sending malformed 802.11 WME frames to a targeted device. A successful exploit could allow the attacker to cause the WLC to reload unexpectedly. The fixed versions are 8.0.140.0, 8.2.130.0, and 8.3.111.0. Cisco Bug IDs: CSCva86353.

Affected products

  • Cisco Wireless Lan Controller: version 5.2.157.0 only; version 5.2.169.0 only; version 6.0_base only; version 7.0_base only; version 7.1_base only; version 7.2_base only; …
  • Cisco Wireless Lan Controller 6.0: version 182.0 only; version 188.0 only; version 196.0 only; version 199.4 only; version 202.0 only
  • Cisco Wireless Lan Controller 7.0: version 98.0 only; version 98.218 only; version 116.0 only; version 220.0 only; version 240.0 only; version 250.0 only; …
  • Cisco Wireless Lan Controller 7.1: version 91.0 only
  • Cisco Wireless Lan Controller 7.2: version 103.0 only
  • Cisco Wireless Lan Controller 7.4: version 1.19 only; version 1.54 only; version 140.0 only

Published 2017-04-06. Last modified 2026-06-17.