PT-2024-7681 · Cisco · Cisco Unified Industrial Wireless
Dj Cole
·
Published
2024-11-06
·
Updated
2025-09-01
·
CVE-2024-20418
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points versions prior to 17.15.1
Catalyst IW9165D Heavy Duty Access Points versions prior to 17.15.1
Catalyst IW9165E Rugged Access Points and Wireless Clients versions prior to 17.15.1
Catalyst IW9167E Heavy Duty Access Points versions prior to 17.15.1
Description
A vulnerability exists in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points. This flaw allows an unauthenticated, remote attacker to perform command injection attacks with root privileges on the underlying operating system. The vulnerability is due to improper validation of input to the web-based management interface. An attacker could exploit this by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges. This vulnerability is actively exploited in the wild.
Recommendations
- Upgrade Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points to version 17.15.1 or later.
- Upgrade Catalyst IW9165D Heavy Duty Access Points to version 17.15.1 or later.
- Upgrade Catalyst IW9165E Rugged Access Points and Wireless Clients to version 17.15.1 or later.
- Upgrade Catalyst IW9167E Heavy Duty Access Points to version 17.15.1 or later.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Unified Industrial Wireless