PT-2017-3107 · Cisco · Cisco Mobility Express 1800 Series Access Points

Published

2017-03-15

·

Updated

2019-10-09

·

CVE-2017-3831

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Mobility Express 1800 Series Access Points versions prior to 8.2.110.0
Description A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication and gain full administrator privileges. The issue is due to improper implementation of authentication for accessing certain web pages using the GUI interface. An attacker could exploit this by sending a crafted HTTP request to the web interface, potentially allowing them to perform unauthorized configuration changes or issue control commands to the affected device.
Recommendations For versions prior to 8.2.110.0, update to version 8.2.110.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation. Avoid using the web-based GUI for critical operations until the update is applied.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02495
CVE-2017-3831

Affected Products

Cisco Mobility Express 1800 Series Access Points