Vulnerability identifier: #VU15409
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0416
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The weakness exists in the web-based interface of Cisco Wireless LAN Controller Software due to incomplete input and validation checking mechanisms in the web-based interface URL request. A remote attacker can request specific URLs via the web-based interface and view sensitive system information.
Affected software
Cisco Wireless LAN Controller
How to mitigate CVE-2018-0416
The vulnerability has been addressed in the versions 8.9(1.65), 8.8(100.0), 8.8(1.176), 8.5(137.11), 8.5(135.0), 8.5(134.102), 8.5(131.8), 8.5(124.106), 8.3(141.10).
Cisco Wireless LAN Controller - addressed in versions 8.3.141.10, 8.5.124.106, 8.5.131.8, 8.5.134.102, 8.5.135.0, 8.5.137.11, 8.8.1.176, 8.8.100.0, 8.9.1.65
External References
Related Security Bulletins