Cisco Wireless LAN Controllers (CVE-2010-2843) Remote Privilege Escalation Vulnerability
BID:43066
Info
Cisco Wireless LAN Controllers (CVE-2010-2843) Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 43066 |
| Class: | Access Validation Error |
| CVE: |
CVE-2010-2843 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2010 12:00AM |
| Updated: | Sep 08 2010 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco WLC Modules for Integrated Services Routers 0 Cisco Wireless Services Modules (WiSM) 0 Cisco Wireless LAN Control 6.0.182 .0 Cisco Wireless LAN Control 5.2.193 .0 Cisco Wireless LAN Control 5.2.178 .0 Cisco Wireless LAN Control 4.2.207 .0 Cisco Wireless LAN Control 4.2.205 .0 Cisco Wireless LAN Control 4.2.176 .51 Cisco Wireless LAN Control 7.0 Cisco Wireless LAN Control 6.0.199.0 Cisco Wireless LAN Control 6.0.196.0 Cisco Wireless LAN Control 6.0.188.0 Cisco Wireless LAN Control 6.0 Cisco Wireless LAN Control 5.2.193.11 Cisco Wireless LAN Control 5.2 Cisco Wireless LAN Control 5.1 Cisco Wireless LAN Control 5.0 Cisco Wireless LAN Control 4.2.209.0 Cisco Wireless LAN Control 4.2.207.54M Cisco Wireless LAN Control 4.2.173.0 Cisco Wireless LAN Control 4.2 M Cisco Wireless LAN Control 4.2 Cisco Catalyst 3750 Series Integrated Wireless LAN Cont 0 Cisco 5500 Wireless LAN Controller (WLC) 0 Cisco 4400 Wireless LAN Controller (WLC) 0 Cisco 4100 Wireless LAN Controller (WLC) 0 Cisco 2100 Wireless LAN Controller (WLC) 0 Cisco 2000 Wireless LAN Controller (WLC) 0 |
| Not Vulnerable: | |
Discussion
Cisco Wireless LAN Controllers (CVE-2010-2843) Remote Privilege Escalation Vulnerability
Cisco Wireless LAN Controllers are prone to a remote privilege-escalation vulnerability. This issue is tracked by Cisco Bug ID CSCsz66726.
An authenticated attacker with read-only privileges can exploit this issue to modify configuration settings, gaining elevated privileges. This may lead to a full compromise of the affected device or aid in further attacks.
Wireless LAN Controller firmware 4.2 and later are affected.
Cisco Wireless LAN Controllers are prone to a remote privilege-escalation vulnerability. This issue is tracked by Cisco Bug ID CSCsz66726.
An authenticated attacker with read-only privileges can exploit this issue to modify configuration settings, gaining elevated privileges. This may lead to a full compromise of the affected device or aid in further attacks.
Wireless LAN Controller firmware 4.2 and later are affected.
Exploit / POC
Cisco Wireless LAN Controllers (CVE-2010-2843) Remote Privilege Escalation Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
Cisco Wireless LAN Controllers (CVE-2010-2843) Remote Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Cisco Wireless LAN Controllers (CVE-2010-2843) Remote Privilege Escalation Vulnerability
References:
References: