PT-2022-6085 · Cisco · Cisco Ios Xe Wireless Controller+1

Published

2022-09-28

·

Updated

2022-10-27

·

CVE-2022-20810

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family (affected versions not specified)
Description A vulnerability in the Simple Network Management Protocol (SNMP) could allow an authenticated, remote attacker to access sensitive information due to insufficient restrictions. This vulnerability allows a sensitive configuration detail to be disclosed. An attacker could exploit this vulnerability by retrieving data through SNMP read-only community access, potentially viewing Service Set Identifier (SSID) preshared keys (PSKs) configured on the affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2023-00023
CVE-2022-20810

Affected Products

Cisco Ios Xe Wireless Controller
Cisco Ios Xe