cbcvebase.
CVE-2022-20695
published 2022-04-15

CVE-2022-20695: A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass…

PriorityP182critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
19.86%
97.1th percentile
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This vulnerability is due to the improper implementation of the password validation algorithm. An attacker could exploit this vulnerability by logging in to an affected device with crafted credentials. A successful exploit could allow the attacker to bypass authentication and log in to the device as an administrator. The attacker could obtain privileges that are the same level as an administrative user but it depends on the crafted credentials. Note: This vulnerability exists because of a non-default device configuration that must be present for it to be exploitable. For details about the vulnerable configuration, see the Vulnerable Products section of this advisory.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscocisco_wireless_lan_controller
ciscowireless_lan_controller

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit requires logging in to the management interface with crafted credentials to bypass authentication
  • The attack vector is the management interface of Cisco WLC; monitor for unexpected or anomalous administrative logins via the management interface
  • Root cause is improper password validation algorithm (CWE-303); detection should focus on authentication success events from unexpected/unauthenticated sources on the WLC management interface
  • ·The vulnerability is only exploitable when a specific non-default device configuration is present; devices without this configuration are not affected
  • ·The privilege level obtained by the attacker depends on the crafted credentials used, not necessarily full admin; scope of compromise may vary per exploitation attempt

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.