PT-2019-2131 · Cisco · Cisco Wireless Lan Controller (Wlc)+1
Published
2019-04-17
·
Updated
2019-10-09
·
CVE-2018-0382
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Wireless LAN Controller (WLC) Software versions 8.1 through 8.5
Description
A vulnerability in the session identification management functionality of the web-based interface could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The issue exists because the software does not properly clear previously assigned session identifiers for a user session when a user authenticates to the web-based interface. An attacker could exploit this by using an existing session identifier to connect to the software, potentially allowing them to hijack an authenticated user's browser session.
Recommendations
For versions 8.1 and 8.5, update to a fixed version to resolve the issue. As a temporary workaround, consider restricting access to the web-based interface to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Wireless Lan Controller (Wlc)
Cisco Wls