// For flags

CVE-2018-15395

Cisco Wireless LAN Controller Software Privilege Escalation Vulnerability

Severity Score

5.4
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, adjacent attacker to gain network access to a Cisco TrustSec domain. Under normal circumstances, this access should be prohibited. The vulnerability is due to the dynamic assignment of Security Group Tags (SGTs) during a wireless roam from one Service Set Identifier (SSID) to another within the Cisco TrustSec domain. An attacker could exploit this vulnerability by attempting to acquire an SGT from other SSIDs within the domain. Successful exploitation could allow the attacker to gain privileged network access that should be prohibited under normal circumstances.

Una vulnerabilidad en los mecanismos de comprobación de autenticación y autorización de Cisco Wireless LAN Controller (WLC) Software podría permitir que un atacante autenticado adyacente obtenga acceso de red a un dominio Cisco TrustSec. En circunstancias normales, el acceso debería estar prohibido. La vulnerabilidad se debe a la asignación dinámica de STG (Security Group Tags) durante un roam inalámbrico de un SSID (Service Set Identifier) a otro en el dominio Cisco TrustSec. Un atacante podría explotar esta vulnerabilidad intentando adquirir un SGT de otros SSID en el dominio. Su explotación con éxito podría permitir que el atacante obtenga privilegios de red que deberían estar prohibidos en otras circunstancias.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-08-17 CVE Reserved
  • 2018-10-17 CVE Published
  • 2023-10-11 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-284: Improper Access Control
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Wireless Lan Controller Software
Search vendor "Cisco" for product "Wireless Lan Controller Software"
8.5\(120.0\)
Search vendor "Cisco" for product "Wireless Lan Controller Software" and version "8.5\(120.0\)"
-
Affected