{"api_version":"1","generated_at":"2026-07-24T19:35:00+00:00","cve":"CVE-2018-0442","urls":{"html":"https://cve.report/CVE-2018-0442","api":"https://cve.report/api/cve/CVE-2018-0442.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-0442","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-0442"},"summary":{"title":"CVE-2018-0442","description":"A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. The vulnerability is due to insufficient condition checks in the part of the code that handles CAPWAP keepalive requests. An attacker could exploit this vulnerability by sending a crafted CAPWAP keepalive packet to a vulnerable Cisco WLC device. A successful exploit could allow the attacker to retrieve the contents of device memory, which could lead to the disclosure of confidential information.","state":"PUBLIC","assigner":"psirt@cisco.com","published_at":"2018-10-17 22:29:00","updated_at":"2020-10-22 16:46:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181017-wlc-capwap-memory-leak","name":"20181017 Cisco Wireless LAN Controller Software Control and Provisioning of Wireless Access Points Protocol Information Disclosure Vulnerability","refsource":"CISCO","tags":["Vendor Advisory"],"title":"Cisco Wireless LAN Controller Software Control and Provisioning of Wireless Access Points Protocol Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1041923","name":"1041923","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"Cisco Wireless LAN Controller CAPWAP Keepalive Request Processing Flaw Lets Remote Users Obtain Potentially Sensitive Information on the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/105664","name":"105664","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Cisco Wireless LAN Controller Software CVE-2018-0442 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-0442","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-0442","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"442","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"wireless_lan_controller_software","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"442","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"wireless_lan_controller_software","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@cisco.com","DATE_PUBLIC":"2018-10-17T16:00:00-0500","ID":"CVE-2018-0442","STATE":"PUBLIC","TITLE":"Cisco Wireless LAN Controller Software Control and Provisioning of Wireless Access Points Protocol Information Disclosure Vulnerability"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Cisco Wireless LAN Controller (WLC) ","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"Cisco"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. The vulnerability is due to insufficient condition checks in the part of the code that handles CAPWAP keepalive requests. An attacker could exploit this vulnerability by sending a crafted CAPWAP keepalive packet to a vulnerable Cisco WLC device. A successful exploit could allow the attacker to retrieve the contents of device memory, which could lead to the disclosure of confidential information."}]},"exploit":[{"lang":"eng","value":"The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory. "}],"impact":{"cvss":{"baseScore":"7.5","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N ","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-200"}]}]},"references":{"reference_data":[{"name":"1041923","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1041923"},{"name":"105664","refsource":"BID","url":"http://www.securityfocus.com/bid/105664"},{"name":"20181017 Cisco Wireless LAN Controller Software Control and Provisioning of Wireless Access Points Protocol Information Disclosure Vulnerability","refsource":"CISCO","url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181017-wlc-capwap-memory-leak"}]},"source":{"advisory":"cisco-sa-20181017-wlc-capwap-memory-leak","defect":[["CSCvf66680"]],"discovery":"INTERNAL"}},"nvd":{"publishedDate":"2018-10-17 22:29:00","lastModifiedDate":"2020-10-22 16:46:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:*","versionEndExcluding":"8.2.170.0","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:*","versionStartIncluding":"8.7","versionEndExcluding":"8.7.102.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:*","versionStartIncluding":"8.6","versionEndExcluding":"8.6.101.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:*","versionStartIncluding":"8.4","versionEndExcluding":"8.5.110.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:*","versionStartIncluding":"8.3","versionEndExcluding":"8.3.140.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"442","Ordinal":"115255","Title":"CVE-2018-0442","CVE":"CVE-2018-0442","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"442","Ordinal":"1","NoteData":"A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. The vulnerability is due to insufficient condition checks in the part of the code that handles CAPWAP keepalive requests. An attacker could exploit this vulnerability by sending a crafted CAPWAP keepalive packet to a vulnerable Cisco WLC device. A successful exploit could allow the attacker to retrieve the contents of device memory, which could lead to the disclosure of confidential information.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"442","Ordinal":"2","NoteData":"2018-10-17","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"442","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}