Vulnerability Description
Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 does not use an adequate message-digest algorithm for a self-signed certificate, which allows remote attackers to bypass intended access restrictions via vectors involving collisions, aka Bug ID CSCtd67660.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Wireless Network Solution Software | 7.0 |
Related Weaknesses (CWE)
References
- http://www.cisco.com/en/US/docs/wireless/controller/release/notes/crn7.0.html
- http://www.cisco.com/en/US/docs/wireless/controller/release/notes/crn7.0.html
FAQ
What is CVE-2010-2978?
CVE-2010-2978 is a vulnerability with a CVSS score of 10.0 (HIGH). Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 does not use an adequate message-digest algorithm for a self-signed certificate, which allows remote attackers to bypass intended acce...
How severe is CVE-2010-2978?
CVE-2010-2978 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2978?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Wireless Network Solution Software.