PT-2022-2222 · Cisco · Cisco Wireless Lan Controller+1

Published

2022-04-13

·

Updated

2022-09-12

·

CVE-2022-20695

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Wireless LAN Controller (WLC) Software versions 8.10.151.0 through 8.10.162.0
Description A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface. This vulnerability is due to the improper implementation of the password validation algorithm. An attacker could exploit this vulnerability by logging in to an affected device with crafted credentials. A successful exploit could allow the attacker to bypass authentication and log in to the device as an administrator. The attacker could obtain privileges that are the same level as an administrative user but it depends on the crafted credentials.
Recommendations For versions 8.10.151.0 through 8.10.162.0, update to version 8.10.171.0 or later to fix the vulnerability. As a temporary workaround, consider resetting the macfilter radius compatibility parameter to its default value (by executing config macfilter radius-compat cisco) or other secure modes, such as "free" (config macfilter radius-compat free).

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02306
CVE-2022-20695

Affected Products

Cisco Wireless Lan Controller
Cisco Wls