// For flags

CVE-2022-20695

Cisco Wireless LAN Controller Management Interface Authentication Bypass Vulnerability

Severity Score

10.0
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This vulnerability is due to the improper implementation of the password validation algorithm. An attacker could exploit this vulnerability by logging in to an affected device with crafted credentials. A successful exploit could allow the attacker to bypass authentication and log in to the device as an administrator. The attacker could obtain privileges that are the same level as an administrative user but it depends on the crafted credentials. Note: This vulnerability exists because of a non-default device configuration that must be present for it to be exploitable. For details about the vulnerable configuration, see the Vulnerable Products section of this advisory.

Una vulnerabilidad en la funcionalidad de autenticación del software Cisco Wireless LAN Controller (WLC) podría permitir a un atacante remoto no autenticado omitir los controles de autenticación e iniciar sesión en el dispositivo mediante la interfaz de administración Esta vulnerabilidad es debido a la implementación inapropiada del algoritmo de comprobación de contraseñas. Un atacante podría aprovechar esta vulnerabilidad al iniciar sesión en un dispositivo afectado con credenciales diseñadas. Una explotación con éxito podría permitir al atacante omitir la autenticación e iniciar sesión en el dispositivo como administrador. El atacante podría alcanzar privilegios del mismo nivel que un usuario administrativo, pero depende de las credenciales diseñadas. Nota: Esta vulnerabilidad se presenta debido a una configuración del dispositivo no predeterminada que debe estar presente para que sea explotable. Para más detalles sobre la configuración vulnerable, consulte la sección Vulnerable Products de este aviso

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2021-11-02 CVE Reserved
  • 2022-04-15 CVE Published
  • 2024-11-06 CVE Updated
  • 2024-11-19 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
  • CWE-303: Incorrect Implementation of Authentication Algorithm
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Virtual Wireless Controller
Search vendor "Cisco" for product "Virtual Wireless Controller"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
3504 Wireless Controller
Search vendor "Cisco" for product "3504 Wireless Controller"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
5520 Wireless Controller
Search vendor "Cisco" for product "5520 Wireless Controller"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
8540 Wireless Controller
Search vendor "Cisco" for product "8540 Wireless Controller"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1540
Search vendor "Cisco" for product "Aironet 1540"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542d
Search vendor "Cisco" for product "Aironet 1542d"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542i
Search vendor "Cisco" for product "Aironet 1542i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1560
Search vendor "Cisco" for product "Aironet 1560"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562d
Search vendor "Cisco" for product "Aironet 1562d"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562e
Search vendor "Cisco" for product "Aironet 1562e"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562i
Search vendor "Cisco" for product "Aironet 1562i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1815
Search vendor "Cisco" for product "Aironet 1815"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1815i
Search vendor "Cisco" for product "Aironet 1815i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1815m
Search vendor "Cisco" for product "Aironet 1815m"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1815t
Search vendor "Cisco" for product "Aironet 1815t"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1815w
Search vendor "Cisco" for product "Aironet 1815w"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1830
Search vendor "Cisco" for product "Aironet 1830"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1830e
Search vendor "Cisco" for product "Aironet 1830e"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1830i
Search vendor "Cisco" for product "Aironet 1830i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1832
Search vendor "Cisco" for product "Aironet 1832"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1850
Search vendor "Cisco" for product "Aironet 1850"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1850e
Search vendor "Cisco" for product "Aironet 1850e"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1850i
Search vendor "Cisco" for product "Aironet 1850i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1852
Search vendor "Cisco" for product "Aironet 1852"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800
Search vendor "Cisco" for product "Aironet 2800"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800e
Search vendor "Cisco" for product "Aironet 2800e"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800i
Search vendor "Cisco" for product "Aironet 2800i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800
Search vendor "Cisco" for product "Aironet 3800"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800e
Search vendor "Cisco" for product "Aironet 3800e"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800i
Search vendor "Cisco" for product "Aironet 3800i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800p
Search vendor "Cisco" for product "Aironet 3800p"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.151.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.151.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 4800
Search vendor "Cisco" for product "Aironet 4800"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Virtual Wireless Controller
Search vendor "Cisco" for product "Virtual Wireless Controller"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
3504 Wireless Controller
Search vendor "Cisco" for product "3504 Wireless Controller"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
5520 Wireless Controller
Search vendor "Cisco" for product "5520 Wireless Controller"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
8540 Wireless Controller
Search vendor "Cisco" for product "8540 Wireless Controller"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1540
Search vendor "Cisco" for product "Aironet 1540"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542d
Search vendor "Cisco" for product "Aironet 1542d"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542i
Search vendor "Cisco" for product "Aironet 1542i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1560
Search vendor "Cisco" for product "Aironet 1560"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562d
Search vendor "Cisco" for product "Aironet 1562d"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562e
Search vendor "Cisco" for product "Aironet 1562e"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562i
Search vendor "Cisco" for product "Aironet 1562i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1815
Search vendor "Cisco" for product "Aironet 1815"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1815i
Search vendor "Cisco" for product "Aironet 1815i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1815m
Search vendor "Cisco" for product "Aironet 1815m"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1815t
Search vendor "Cisco" for product "Aironet 1815t"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1815w
Search vendor "Cisco" for product "Aironet 1815w"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1830
Search vendor "Cisco" for product "Aironet 1830"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1830e
Search vendor "Cisco" for product "Aironet 1830e"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1830i
Search vendor "Cisco" for product "Aironet 1830i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1832
Search vendor "Cisco" for product "Aironet 1832"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1850
Search vendor "Cisco" for product "Aironet 1850"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1850e
Search vendor "Cisco" for product "Aironet 1850e"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1850i
Search vendor "Cisco" for product "Aironet 1850i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1852
Search vendor "Cisco" for product "Aironet 1852"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800
Search vendor "Cisco" for product "Aironet 2800"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800e
Search vendor "Cisco" for product "Aironet 2800e"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800i
Search vendor "Cisco" for product "Aironet 2800i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800
Search vendor "Cisco" for product "Aironet 3800"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800e
Search vendor "Cisco" for product "Aironet 3800e"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800i
Search vendor "Cisco" for product "Aironet 3800i"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800p
Search vendor "Cisco" for product "Aironet 3800p"
--
Safe
Cisco
Search vendor "Cisco"
Wireless Lan Controller 8.10.162.0
Search vendor "Cisco" for product "Wireless Lan Controller 8.10.162.0"
*-
Affected
in Cisco
Search vendor "Cisco"
Aironet 4800
Search vendor "Cisco" for product "Aironet 4800"
--
Safe