Vulnerability Name: | CVE-2009-0062 (CCN-48480) | ||||||||
Assigned: | 2009-02-04 | ||||||||
Published: | 2009-02-04 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | Unspecified vulnerability in the Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.2.173.0 allows remote authenticated users to gain privileges via unknown vectors, as demonstrated by escalation from the (1) Lobby Admin and (2) Local Management User privilege levels. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C) 6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-0062 Source: CCN Type: SA33749 Cisco Products Denial of Service and Security Bypass Vulnerabilities Source: SECUNIA Type: UNKNOWN 33749 Source: CCN Type: SECTRACK ID: 1021678 Cisco Wireless LAN Controller Lets Remote Authenticated Users Gain Elevated Privileges Source: CISCO Type: Vendor Advisory 20090204 Multiple Vulnerabilities in Cisco Wireless LAN Controllers Source: CCN Type: cisco-sa-20090204-wlc Multiple Vulnerabilities in Cisco Wireless LAN Controllers Source: CCN Type: OSVDB ID: 52375 Cisco Multiple Wireless Products Unspecified Local Privilege Escalation Source: BID Type: UNKNOWN 33608 Source: CCN Type: BID-33608 Multiple Cisco Wireless LAN Controllers Multiple Remote Vulnerabilities Source: SECTRACK Type: UNKNOWN 1021678 Source: XF Type: UNKNOWN cisco-wlc-unspecified-privilege-escalation(48480) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |