CVE-2015-6314
published 2016-01-15CVE-2015-6314: Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change configuration…
PriorityP358critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.98%
85.7th percentile
Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change configuration settings via unspecified vectors, aka Bug ID CSCuw06153.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_unauthorized_access | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xg4p-hrwg-fqj6: Cisco Wireless LAN Controller (WLC) devices with software 7
ghsa_unreviewed·2022-05-13
CVE-2015-6314 [CRITICAL] CWE-287 GHSA-xg4p-hrwg-fqj6: Cisco Wireless LAN Controller (WLC) devices with software 7
Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change configuration settings via unspecified vectors, aka Bug ID CSCuw06153.
Cisco
Cisco Wireless LAN Controller Unauthorized Access Vulnerability
vendor_cisco·2016-01-13·CVSS 10.0
CVE-2015-6314 [CRITICAL] CWE-287 Cisco Wireless LAN Controller Unauthorized Access Vulnerability
Cisco Wireless LAN Controller Unauthorized Access Vulnerability
Devices running Cisco Wireless LAN Controller (WLC) software versions 7.6.120.0 or later, 8.0 or later, or 8.1 or later contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to modify the configuration of the device.
An attacker who can connect to an affected device could exploit this vulnerability. A successful exploit may compromise the device completely. Customers are advised to upgrade to a version of Cisco WLC software that addresses this vulnerability.
There are no workarounds that address this vulnerability.
Cisco has released software updates that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center
Cisco
Cisco Wireless LAN Controller Unauthorized Access Vulnerability
vendor_cisco
CVE-2015-6314 Cisco Wireless LAN Controller Unauthorized Access Vulnerability
CVE-2015-6314: Cisco Wireless LAN Controller Unauthorized Access Vulnerability
Devices running Cisco Wireless LAN Controller (WLC) software versions 7.6.120.0 or later, 8.0 or later, or 8.1 or later contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to modify the configuration of the device. An attacker who can connect to an affected device could exploit this vulnerability. A successful exploit may compromise the device completely. Customers are advised to upgrade to a version of Cisco WLC software that addresses this vulnerability. There are no
CWE: CWE-287, CWE-287
Bug IDs: CSCuw06153
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-01-15
Published