CVE-2015-6336
published 2016-01-15CVE-2015-6336: Cisco Aironet 1800 devices with software 7.2, 7.3, 7.4, 8.1(112.3), 8.1(112.4), and 8.1(15.14) have a default account, which makes it easier for remote…
PriorityP344high7.3CVSS 3.0
AVNACLPRNUINSUCLILAL
EPSS
1.39%
69.3th percentile
Cisco Aironet 1800 devices with software 7.2, 7.3, 7.4, 8.1(112.3), 8.1(112.4), and 8.1(15.14) have a default account, which makes it easier for remote attackers to obtain access via unspecified vectors, aka Bug ID CSCuw58062.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | aironet_1800_series_access_point_default_static_account_credentials | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
CVSS provenance
nvdv3.07.3HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Aironet 1800 Series Access Point Default Static Account Credentials Vulnerability
vendor_cisco·2016-01-14·CVSS 7.5
CVE-2015-6336 [HIGH] CWE-255 Cisco Aironet 1800 Series Access Point Default Static Account Credentials Vulnerability
Cisco Aironet 1800 Series Access Point Default Static Account Credentials Vulnerability
A vulnerability in Cisco Aironet 1800 Series Access Point devices could allow an unauthenticated, remote attacker to log in to the device by using a default account that has a static password. By default, the account does not have full administrative privileges.
The vulnerability is due to the presence of a default user account that is created when the device is installed. An attacker could exploit this vulnerability by logging in to the device by using the default account, which could allow the attacker to gain unauthorized access to the device.
Cisco released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
This advisory is available at t
Cisco
Cisco Aironet 1800 Series Access Point Default Static Account Credentials Vulnerability
vendor_cisco
CVE-2015-6336 Cisco Aironet 1800 Series Access Point Default Static Account Credentials Vulnerability
CVE-2015-6336: Cisco Aironet 1800 Series Access Point Default Static Account Credentials Vulnerability
A vulnerability in Cisco Aironet 1800 Series Access Point devices could allow an unauthenticated, remote attacker to log in to the device by using a default account that has a static password. By default, the account does not have full administrative privileges. The vulnerability is due to the presence of a default user account that is created when the device is installed. An attacker could exploit this vulnerability by logging in to the device by using the default account, which could allow the attacker to gain unauthorized access to the device. Cisco released software updates that address this vulnerability. There are no
CWE: CWE-255, CWE-255
Bug IDs: CSCuw58062
GHSA
GHSA-6v88-g42x-cgfp: Cisco Aironet 1800 devices with software 7
ghsa_unreviewed·2022-05-17
CVE-2015-6336 [HIGH] GHSA-6v88-g42x-cgfp: Cisco Aironet 1800 devices with software 7
Cisco Aironet 1800 devices with software 7.2, 7.3, 7.4, 8.1(112.3), 8.1(112.4), and 8.1(15.14) have a default account, which makes it easier for remote attackers to obtain access via unspecified vectors, aka Bug ID CSCuw58062.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-01-15
Published