Vulnerability Name: | CVE-2014-0703 (CCN-91605) | ||||||||
Assigned: | 2014-03-05 | ||||||||
Published: | 2014-03-05 | ||||||||
Updated: | 2014-03-07 | ||||||||
Summary: | Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the administrative HTTP server, which allows remote attackers to bypass intended access restrictions by connecting to an Aironet access point on which this server had been disabled ineffectively, aka Bug ID CSCuf66202. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-362 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-0703 Source: CCN Type: SA57128 Cisco Wireless LAN Controllers Multiple Security Bypass and Denial of Service Vulnerabilities Source: CCN Type: cisco-sa-20140305-wlc Multiple Vulnerabilities in Cisco Wireless LAN Controllers Source: CISCO Type: Vendor Advisory 20140305 Multiple Vulnerabilities in Cisco Wireless LAN Controllers Source: CCN Type: BID-65983 Cisco Wireless LAN Controller CVE-2014-0703 Unauthorized Access Vulnerability Source: XF Type: UNKNOWN cisco-wlc-cve20140703-sec-bypass(91605) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |