PT-2022-2222 · Cisco · Cisco Wireless Lan Controller+1
Published
2022-04-13
·
Updated
2022-09-12
·
CVE-2022-20695
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Wireless LAN Controller (WLC) Software versions 8.10.151.0 through 8.10.162.0
Description
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface. This vulnerability is due to the improper implementation of the password validation algorithm. An attacker could exploit this vulnerability by logging in to an affected device with crafted credentials. A successful exploit could allow the attacker to bypass authentication and log in to the device as an administrator. The attacker could obtain privileges that are the same level as an administrative user but it depends on the crafted credentials.
Recommendations
For versions 8.10.151.0 through 8.10.162.0, update to version 8.10.171.0 or later to fix the vulnerability.
As a temporary workaround, consider resetting the
macfilter radius compatibility parameter to its default value (by executing config macfilter radius-compat cisco) or other secure modes, such as "free" (config macfilter radius-compat free).Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Wireless Lan Controller
Cisco Wls