CVE-2018-0245
published 2018-05-02CVE-2018-0245: A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.33%
81.7th percentile
A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to incomplete input and validation checking mechanisms in the REST API URL request. An attacker could exploit this vulnerability by sending a malicious URL to the REST API. If successful, an exploit could allow the attacker to view sensitive system information. Cisco Bug IDs: CSCvg89442.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | 5500_and_8500_series_wireless_lan_controller | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco 5500 and 8500 Series Wireless LAN Controller Information Disclosure Vulnerability
vendor_cisco·2018-05-02·CVSS 6.5
CVE-2018-0245 [MEDIUM] CWE-269 Cisco 5500 and 8500 Series Wireless LAN Controller Information Disclosure Vulnerability
Cisco 5500 and 8500 Series Wireless LAN Controller Information Disclosure Vulnerability
A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited.
The vulnerability is due to incomplete input and validation checking mechanisms in the REST API URL request. An attacker could exploit this vulnerability by sending a malicious URL to the REST API. If successful, an exploit could allow the attacker to view sensitive system information.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco
Cisco
Cisco 5500 and 8500 Series Wireless LAN Controller Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0245 Cisco 5500 and 8500 Series Wireless LAN Controller Information Disclosure Vulnerability
CVE-2018-0245: Cisco 5500 and 8500 Series Wireless LAN Controller Information Disclosure Vulnerability
A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to incomplete input and validation checking mechanisms in the REST API URL request. An attacker could exploit this vulnerability by sending a malicious URL to the REST API. If successful, an exploit could allow the attacker to view sensitive system information. There are no
CVSS: 3.0
CWE: CWE-269, CWE-269
Bug IDs: CSCvg89442
GHSA
GHSA-p33r-x4hg-wvgw: A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker t
ghsa_unreviewed·2022-05-13
CVE-2018-0245 [MEDIUM] CWE-269 GHSA-p33r-x4hg-wvgw: A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker t
A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to incomplete input and validation checking mechanisms in the REST API URL request. An attacker could exploit this vulnerability by sending a malicious URL to the REST API. If successful, an exploit could allow the attacker to view sensitive system information. Cisco Bug IDs: CSCvg89442.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/104123http://www.securitytracker.com/id/1040823https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180502-wlc-idhttp://www.securityfocus.com/bid/104123http://www.securitytracker.com/id/1040823https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180502-wlc-id
2018-05-02
Published