PT-2018-8700 · Cisco · Cisco Aironet 2800 Series Access Points+7

Published

2018-05-02

·

Updated

2019-10-09

·

CVE-2018-0250

CVSS v3.1

4.1

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Aironet 1560 Series Access Points (affected versions not specified) Cisco Aironet 1810 Series OfficeExtend Access Points (affected versions not specified) Cisco Aironet 1810w Series Access Points (affected versions not specified) Cisco Aironet 1815 Series Access Points (affected versions not specified) Cisco Aironet 1830 Series Access Points (affected versions not specified) Cisco Aironet 1850 Series Access Points (affected versions not specified) Cisco Aironet 2800 Series Access Points (affected versions not specified) Cisco Aironet 3800 Series Access Points (affected versions not specified)
Description: A vulnerability in Central Web Authentication with FlexConnect Access Points could allow an authenticated, adjacent attacker to bypass a configured FlexConnect access control list (ACL). The issue arises because the Access Point ignores the ACL download from the client during authentication. An attacker could exploit this by connecting to the targeted device with a vulnerable configuration, potentially allowing them to bypass the configured client FlexConnect ACL.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-0250

Affected Products

Cisco Aironet 1560 Series Access Points
Cisco Aironet 1810 Series Officeextend Access Points
Cisco Aironet 1810W Series Access Points
Cisco Aironet 1815 Series Access Points
Cisco Aironet 1830 Series Access Points
Cisco Aironet 1850 Series Access Points
Cisco Aironet 2800 Series Access Points
Cisco Aironet 3800 Series Access Points