CVE-2016-1418
Summary
| CVE | CVE-2016-1418 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-06-08 14:59:00 UTC |
| Updated | 2016-06-15 18:42:00 UTC |
| Description | Cisco Aironet Access Point Software 8.2(100.0) on 1830e, 1830i, 1850e, 1850i, 2800, and 3800 access points allows local users to obtain Linux root access via crafted CLI command parameters, aka Bug ID CSCuy64037. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Aironet 1830e | - | All | All | All |
| Hardware | Cisco | Aironet 1830e | - | All | All | All |
| Hardware | Cisco | Aironet 1830i | - | All | All | All |
| Hardware | Cisco | Aironet 1830i | - | All | All | All |
| Hardware | Cisco | Aironet 1850e | - | All | All | All |
| Hardware | Cisco | Aironet 1850e | - | All | All | All |
| Hardware | Cisco | Aironet 1850i | - | All | All | All |
| Hardware | Cisco | Aironet 1850i | - | All | All | All |
| Hardware | Cisco | Aironet 2800 | - | All | All | All |
| Hardware | Cisco | Aironet 2800 | - | All | All | All |
| Hardware | Cisco | Aironet 3800 | - | All | All | All |
| Hardware | Cisco | Aironet 3800 | - | All | All | All |
| Application | Cisco | Aironet Access Point Software | 8.2_(100.0) | All | All | All |
| Application | Cisco | Aironet Access Point Software | 8.2_\(100.0\) | All | All | All |
| Application | Cisco | Aironet Access Point Software | 8.2_\(100.0\) | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Aironet Access Points Command-Line Interpreter Linux Shell Command Injection Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| Cisco Aironet CLI Input Validation Flaw Lets Local Users Obtain Root Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.