CVE-2016-6362
published 2016-08-22CVE-2016-6362: Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.110.0, 8.2.12x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow local users to gain…
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.40%
31.8th percentile
Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.110.0, 8.2.12x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow local users to gain privileges via crafted CLI parameters, aka Bug ID CSCuz24725.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | aironet_1800_2800_and_3800_series_access_point_platforms | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Aironet 1800, 2800, and 3800 Series Access Point Platforms CLI Privilege Escalation Vulnerability
vendor_cisco·2016-08-17·CVSS 6.8
CVE-2016-6362 [MEDIUM] CWE-264 Cisco Aironet 1800, 2800, and 3800 Series Access Point Platforms CLI Privilege Escalation Vulnerability
Cisco Aironet 1800, 2800, and 3800 Series Access Point Platforms CLI Privilege Escalation Vulnerability
A vulnerability in command execution from the command line-interface (CLI) of Cisco Access Point (AP) platforms could allow an authenticated, local attacker to perform privilege escalation to root-level privileges.
The vulnerability occurs because user input is not properly sanitized for certain commands at the CLI. An attacker could exploit this vulnerability by authenticating to the affected device, crafting user input parameters for certain commands, and executing the command at the CLI. An exploit could allow the attacker to elevate privileges to the root level.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerab
Cisco
Cisco Aironet 1800, 2800, and 3800 Series Access Point Platforms CLI Privilege Escalation Vulnerability
vendor_cisco
CVE-2016-6362 Cisco Aironet 1800, 2800, and 3800 Series Access Point Platforms CLI Privilege Escalation Vulnerability
CVE-2016-6362: Cisco Aironet 1800, 2800, and 3800 Series Access Point Platforms CLI Privilege Escalation Vulnerability
A vulnerability in command execution from the command line-interface (CLI) of Cisco Access Point (AP) platforms could allow an authenticated, local attacker to perform privilege escalation to root -level privileges. The vulnerability occurs because user input is not properly sanitized for certain commands at the CLI. An attacker could exploit this vulnerability by authenticating to the affected device, crafting user input parameters for certain commands, and executing the command at the CLI. An exploit could allow the attacker to elevate privileges to the root level. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-264, CWE-264
Bug
GHSA
GHSA-ch9m-8qr6-5wwv: Cisco Aironet 1800, 2800, and 3800 devices with software before 8
ghsa_unreviewed·2022-05-17
CVE-2016-6362 [HIGH] GHSA-ch9m-8qr6-5wwv: Cisco Aironet 1800, 2800, and 3800 devices with software before 8
Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.110.0, 8.2.12x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow local users to gain privileges via crafted CLI parameters, aka Bug ID CSCuz24725.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-aap1http://www.securityfocus.com/bid/92513http://www.securitytracker.com/id/1036644http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-aap1http://www.securityfocus.com/bid/92513http://www.securitytracker.com/id/1036644
2016-08-22
Published