7.5
CVE-2018-0442
- EPSS 1.41%
- Veröffentlicht 17.10.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:14
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. The vulnerability is due to insufficient condition checks in the part of the code that handles CAPWAP keepalive requests. An attacker could exploit this vulnerability by sending a crafted CAPWAP keepalive packet to a vulnerable Cisco WLC device. A successful exploit could allow the attacker to retrieve the contents of device memory, which could lead to the disclosure of confidential information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Wireless Lan Controller Software Version < 8.2.170.0
Cisco ≫ Wireless Lan Controller Software Version >= 8.3 < 8.3.140.0
Cisco ≫ Wireless Lan Controller Software Version >= 8.4 < 8.5.110.0
Cisco ≫ Wireless Lan Controller Software Version >= 8.6 < 8.6.101.0
Cisco ≫ Wireless Lan Controller Software Version >= 8.7 < 8.7.102.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.41% | 0.798 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
psirt@cisco.com | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.