CVE-2018-0382
published 2019-04-17CVE-2018-0382: A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow…
PriorityP346high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
2.04%
78.9th percentile
A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not properly clear previously assigned session identifiers for a user session when a user authenticates to the web-based interface. An attacker could exploit this vulnerability by using an existing session identifier to connect to the software through the web-based interface. Successful exploitation could allow the attacker to hijack an authenticated user's browser session on the system. Versions 8.1 and 8.5 are affected.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_wireless_lan_controller | >= unspecified < 8.5(144.5) | 8.5(144.5) |
| cisco | wireless_lan_controller | — | — |
| cisco | wireless_lan_controller_software | — | — |
| cisco | wireless_lan_controller_software | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Wireless LAN Controller Software Session Hijacking Vulnerability
vendor_cisco·2019-04-17·CVSS 5.3
CVE-2018-0382 [MEDIUM] CWE-287 Cisco Wireless LAN Controller Software Session Hijacking Vulnerability
Cisco Wireless LAN Controller Software Session Hijacking Vulnerability
A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system.
The vulnerability exists because the affected software does not properly clear previously assigned session identifiers for a user session when a user authenticates to the web-based interface. An attacker could exploit this vulnerability by using an existing session identifier to connect to the software through the web-based interface. Successful exploitation could allow the attacker to hijack an authenticated user's browser session on the system.
There are no workarounds that
Cisco
Cisco Wireless LAN Controller Software Session Hijacking Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0382 Cisco Wireless LAN Controller Software Session Hijacking Vulnerability
CVE-2018-0382: Cisco Wireless LAN Controller Software Session Hijacking Vulnerability
A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not properly clear previously assigned session identifiers for a user session when a user authenticates to the web-based interface. An attacker could exploit this vulnerability by using an existing session identifier to connect to the software through the web-based interface. Successful exploitation could allow the attacker to hijack an authenticated user's browser session on the system. There are no
CV
GHSA
GHSA-xf8h-gv6j-fvjf: A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software coul
ghsa_unreviewed·2022-05-13
CVE-2018-0382 [HIGH] CWE-287 GHSA-xf8h-gv6j-fvjf: A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software coul
A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not properly clear previously assigned session identifiers for a user session when a user authenticates to the web-based interface. An attacker could exploit this vulnerability by using an existing session identifier to connect to the software through the web-based interface. Successful exploitation could allow the attacker to hijack an authenticated user's browser session on the system. Versions 8.1 and 8.5 are affected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-04-17
Published