PT-2015-3189 · Cisco · Cisco Wireless Lan Controller+1
Published
2015-06-25
·
Updated
2016-12-28
·
CVE-2015-4224
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Wireless LAN Controller versions 7.0(240.0)
Description
The issue allows local users to execute arbitrary OS commands in a privileged context via crafted CLI commands. This is due to insufficient input validation, which could enable an attacker to read, write, and overwrite any file on the system or execute arbitrary code. To exploit this, an attacker must authenticate and have local access to the targeted device.
Recommendations
For version 7.0(240.0), update to a newer version that includes the fix for this issue, as confirmed by Cisco.
As a temporary workaround, consider restricting access to the CLI to minimize the risk of exploitation.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Wireless Lan Controller
Cisco Wls