CVE-2017-3831
published 2017-03-15CVE-2017-3831: A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass…
PriorityP265critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
5.27%
91.6th percentile
A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. The vulnerability is due to improper implementation of authentication for accessing certain web pages using the GUI interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface of the affected system. A successful exploit could allow the attacker to bypass authentication and perform unauthorized configuration changes or issue control commands to the affected device. This vulnerability affects Cisco Mobility Express 1800 Series Access Points running a software version prior to 8.2.110.0. Cisco Bug IDs: CSCuy68219.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | mobility_express_1800_access_point_series | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit involves sending a crafted HTTP request to the web-based GUI interface of the affected device to bypass authentication ↗
- →The authentication bypass targets specific web pages within the GUI; monitor for unauthenticated access to admin/configuration web pages on Cisco Mobility Express 1800 APs ↗
- →Successful exploitation grants full administrator privileges to an unauthenticated remote attacker; alert on unauthorized configuration changes or control commands issued via the web GUI ↗
- ·Vulnerability affects Cisco Mobility Express 1800 Series Access Points running software versions prior to 8.2.110.0 only; devices on 8.2.110.0 or later are not affected ↗
- ·No workarounds exist for this vulnerability; patching to the fixed software version is the only mitigation ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Mobility Express 1800 Access Point Series Authentication Bypass Vulnerability
vendor_cisco·2017-03-15·CVSS 9.8
CVE-2017-3831 [CRITICAL] CWE-264 Cisco Mobility Express 1800 Access Point Series Authentication Bypass Vulnerability
Cisco Mobility Express 1800 Access Point Series Authentication Bypass Vulnerability
A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges.
The vulnerability is due to improper implementation of authentication for accessing certain web pages using the GUI interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface of the affected system. A successful exploit could allow the attacker to bypass authentication and perform unauthorized configuration changes or issue control commands to the affected device.
Cisco has released software updates that address this vulnerability. T
Cisco
Cisco Mobility Express 1800 Access Point Series Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3831 Cisco Mobility Express 1800 Access Point Series Authentication Bypass Vulnerability
CVE-2017-3831: Cisco Mobility Express 1800 Access Point Series Authentication Bypass Vulnerability
A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. The vulnerability is due to improper implementation of authentication for accessing certain web pages using the GUI interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface of the affected system. A successful exploit could allow the attacker to bypass authentication and perform unauthorized configuration changes or issue control commands to the affected device. Cisco has released software updates that address this vuln
GHSA
GHSA-p3g2-f65q-g6rx: A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass aut
ghsa_unreviewed·2022-05-13
CVE-2017-3831 [CRITICAL] CWE-287 GHSA-p3g2-f65q-g6rx: A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass aut
A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. The vulnerability is due to improper implementation of authentication for accessing certain web pages using the GUI interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface of the affected system. A successful exploit could allow the attacker to bypass authentication and perform unauthorized configuration changes or issue control commands to the affected device. This vulnerability affects Cisco Mobility Express 1800 Series Access Points running a software version prior to 8.2.110.0. Cisco Bug IDs: CSCuy68219.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-03-15
Published