A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This vulnerability is due to the improper implementation of the password validation algorithm. An attacker could exploit this vulnerability by logging in to an affected device with crafted credentials. A successful exploit could allow the attacker to bypass authentication and log in to the device as an administrator. The attacker could obtain privileges that are the same level as an administrative user but it depends on the crafted credentials. Note: This vulnerability exists because of a non-default device configuration that must be present for it to be exploitable. For details about the vulnerable configuration, see the Vulnerable Products section of this advisory.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
3504 Wireless Controller
Subscribe
5520 Wireless Controller
Subscribe
8540 Wireless Controller
Subscribe
Aironet 1540
Subscribe
Aironet 1542d
Subscribe
Aironet 1542i
Subscribe
Aironet 1560
Subscribe
Aironet 1562d
Subscribe
Aironet 1562e
Subscribe
Aironet 1562i
Subscribe
Aironet 1815
Subscribe
Aironet 1815i
Subscribe
Aironet 1815m
Subscribe
Aironet 1815t
Subscribe
Aironet 1815w
Subscribe
Aironet 1830
Subscribe
Aironet 1830e
Subscribe
Aironet 1830i
Subscribe
Aironet 1832
Subscribe
Aironet 1850
Subscribe
Aironet 1850e
Subscribe
Aironet 1850i
Subscribe
Aironet 1852
Subscribe
Aironet 2800
Subscribe
Aironet 2800e
Subscribe
Aironet 2800i
Subscribe
Aironet 3800
Subscribe
Aironet 3800e
Subscribe
Aironet 3800i
Subscribe
Aironet 3800p
Subscribe
Aironet 4800
Subscribe
Virtual Wireless Controller
Subscribe
Wireless Lan Controller 8.10.151.0
Subscribe
Wireless Lan Controller 8.10.162.0
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-25945 | A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This vulnerability is due to the improper implementation of the password validation algorithm. An attacker could exploit this vulnerability by logging in to an affected device with crafted credentials. A successful exploit could allow the attacker to bypass authentication and log in to the device as an administrator. The attacker could obtain privileges that are the same level as an administrative user but it depends on the crafted credentials. Note: This vulnerability exists because of a non-default device configuration that must be present for it to be exploitable. For details about the vulnerable configuration, see the Vulnerable Products section of this advisory. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 06 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-06T16:26:54.535Z
Reserved: 2021-11-02T00:00:00
Link: CVE-2022-20695
Updated: 2024-08-03T02:24:48.589Z
Status : Modified
Published: 2022-04-15T15:15:12.917
Modified: 2024-11-21T06:43:20.707
Link: CVE-2022-20695
No data.
OpenCVE Enrichment
No data.
EUVD