PT-2019-2131 · Cisco · Cisco Wireless Lan Controller (Wlc)+1

Published

2019-04-17

·

Updated

2019-10-09

·

CVE-2018-0382

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Wireless LAN Controller (WLC) Software versions 8.1 through 8.5
Description A vulnerability in the session identification management functionality of the web-based interface could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The issue exists because the software does not properly clear previously assigned session identifiers for a user session when a user authenticates to the web-based interface. An attacker could exploit this by using an existing session identifier to connect to the software, potentially allowing them to hijack an authenticated user's browser session.
Recommendations For versions 8.1 and 8.5, update to a fixed version to resolve the issue. As a temporary workaround, consider restricting access to the web-based interface to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01892
CVE-2018-0382

Affected Products

Cisco Wireless Lan Controller (Wlc)
Cisco Wls