CVE-2016-1418
published 2016-06-08CVE-2016-1418: Cisco Aironet Access Point Software 8.2(100.0) on 1830e, 1830i, 1850e, 1850i, 2800, and 3800 access points allows local users to obtain Linux root access via…
PriorityP338high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.36%
28.5th percentile
Cisco Aironet Access Point Software 8.2(100.0) on 1830e, 1830i, 1850e, 1850i, 2800, and 3800 access points allows local users to obtain Linux root access via crafted CLI command parameters, aka Bug ID CSCuy64037.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_points | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Aironet Access Points Command-Line Interpreter Linux Shell Command Injection Vulnerability
vendor_cisco·2016-06-06·CVSS 6.8
CVE-2016-1418 [MEDIUM] CWE-20 Cisco Aironet Access Points Command-Line Interpreter Linux Shell Command Injection Vulnerability
Cisco Aironet Access Points Command-Line Interpreter Linux Shell Command Injection Vulnerability
A vulnerability in the command-line interpreter of Cisco Aironet 1800, 2800, and 3800 Series Access Points could allow an authenticated, local attacker to inject commands in the Linux shell. The commands could be executed with root-level privileges.
The vulnerability is due to improper sanitization of user-supplied input for parameters of command-line interface (CLI) commands. An attacker could exploit this vulnerability by authenticating to the affected device and executing a subset of CLI commands with crafted input for those parameters. A successful exploit could allow the attacker to execute Linux shell commands with root-level privileges on the affected device.
Cisco has released softwa
Cisco
Cisco Aironet Access Points Command-Line Interpreter Linux Shell Command Injection Vulnerability
vendor_cisco
CVE-2016-1418 Cisco Aironet Access Points Command-Line Interpreter Linux Shell Command Injection Vulnerability
CVE-2016-1418: Cisco Aironet Access Points Command-Line Interpreter Linux Shell Command Injection Vulnerability
A vulnerability in the command-line interpreter of Cisco Aironet 1800, 2800, and 3800 Series Access Points could allow an authenticated, local attacker to inject commands in the Linux shell. The commands could be executed with root -level privileges. The vulnerability is due to improper sanitization of user-supplied input for parameters of command-line interface (CLI) commands. An attacker could exploit this vulnerability by authenticating to the affected device and executing a subset of CLI commands with crafted input for those parameters. A successful exploit could allow the attacker to execute Linux shell commands with root -level privileges on the affected device. Cisco has r
GHSA
GHSA-9jph-wqrp-7q3w: Cisco Aironet Access Point Software 8
ghsa_unreviewed·2022-05-17
CVE-2016-1418 [HIGH] CWE-20 GHSA-9jph-wqrp-7q3w: Cisco Aironet Access Point Software 8
Cisco Aironet Access Point Software 8.2(100.0) on 1830e, 1830i, 1850e, 1850i, 2800, and 3800 access points allows local users to obtain Linux root access via crafted CLI command parameters, aka Bug ID CSCuy64037.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-06-08
Published