CVE-2010-2842
published 2010-09-10CVE-2010-2842: Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the…
PriorityP338critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
1.48%
71.3th percentile
Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different vulnerability than CVE-2010-2843 and CVE-2010-3033.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controllers | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h6gm-f98p-r6x3: Cisco Wireless LAN Controller (WLC) software, possibly 4
ghsa_unreviewed·2022-05-17·CVSS 9.0
CVE-2010-3033 [CRITICAL] GHSA-h6gm-f98p-r6x3: Cisco Wireless LAN Controller (WLC) software, possibly 4
Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different vulnerability than CVE-2010-2842 and CVE-2010-2843.
GHSA
GHSA-h8c3-9hwv-w4vc: Cisco Wireless LAN Controller (WLC) software, possibly 4
ghsa_unreviewed·2022-05-17·CVSS 9.0
CVE-2010-2843 [CRITICAL] GHSA-h8c3-9hwv-w4vc: Cisco Wireless LAN Controller (WLC) software, possibly 4
Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different vulnerability than CVE-2010-2842 and CVE-2010-3033.
GHSA
GHSA-chhf-xpc8-8x22: Cisco Wireless LAN Controller (WLC) software, possibly 4
ghsa_unreviewed·2022-05-17·CVSS 9.0
CVE-2010-2842 [CRITICAL] GHSA-chhf-xpc8-8x22: Cisco Wireless LAN Controller (WLC) software, possibly 4
Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different vulnerability than CVE-2010-2843 and CVE-2010-3033.
Cisco
Multiple Vulnerabilities in Cisco Wireless LAN Controllers
vendor_cisco·2010-09-08·CVSS 9.0
CVE-2010-0574 [CRITICAL] CWE-264 Multiple Vulnerabilities in Cisco Wireless LAN Controllers
Multiple Vulnerabilities in Cisco Wireless LAN Controllers
The Cisco Wireless LAN Controller (WLC) product family is affected by
these vulnerabilities:
Two denial of service (DoS) vulnerabilities
Three privilege escalation vulnerabilities
Two access control list (ACL) bypass vulnerabilities
Note: These vulnerabilities are independent of one another. A device may be
affected by one vulnerability and not affected by another.
Cisco has released software updates that address these vulnerabilities.
There are no workarounds to mitigate these
vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100908-wlc.
Cisco
Multiple Vulnerabilities in Cisco Wireless LAN Controllers
vendor_cisco
CVE-2010-2842 Multiple Vulnerabilities in Cisco Wireless LAN Controllers
CVE-2010-2842: Multiple Vulnerabilities in Cisco Wireless LAN Controllers
The Cisco Wireless LAN Controller (WLC) product family is affected by these vulnerabilities: Two denial of service (DoS) vulnerabilities Three privilege escalation vulnerabilities Two access control list (ACL) bypass vulnerabilities Note: These vulnerabilities are independent of one another. A device may be affected by one vulnerability and not affected by another. Cisco has released software updates that address these vulnerabilities. There are no
CWE: CWE-264, CWE-399, CWE-264, CWE-399
Bug IDs: CSCta56653, CSCtd16938, CSCtc91431, CSCsz66726, CSCtc93837
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2010-09-10
Published