CRITICAL · 10.0

CVE-2022-20695

A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the ...

Vulnerability Description

A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This vulnerability is due to the improper implementation of the password validation algorithm. An attacker could exploit this vulnerability by logging in to an affected device with crafted credentials. A successful exploit could allow the attacker to bypass authentication and log in to the device as an administrator. The attacker could obtain privileges that are the same level as an administrative user but it depends on the crafted credentials. Note: This vulnerability exists because of a non-default device configuration that must be present for it to be exploitable. For details about the vulnerable configuration, see the Vulnerable Products section of this advisory.

CVSS Score

10.0

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CiscoWireless Lan Controller 8.10.151.0All versions
CiscoWireless Lan Controller 8.10.162.0All versions
CiscoVirtual Wireless Controller-
Cisco3504 Wireless Controller-
Cisco5520 Wireless Controller-
Cisco8540 Wireless Controller-
CiscoAironet 1540-
CiscoAironet 1542D-
CiscoAironet 1542I-
CiscoAironet 1560-
CiscoAironet 1562D-
CiscoAironet 1562E-
CiscoAironet 1562I-
CiscoAironet 1815-
CiscoAironet 1815I-
CiscoAironet 1815M-
CiscoAironet 1815T-
CiscoAironet 1815W-
CiscoAironet 1830-
CiscoAironet 1830E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-20695?

CVE-2022-20695 is a vulnerability with a CVSS score of 10.0 (CRITICAL). A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the ...

How severe is CVE-2022-20695?

CVE-2022-20695 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-20695?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Wireless Lan Controller 8.10.151.0, Cisco Wireless Lan Controller 8.10.162.0, Cisco Virtual Wireless Controller, Cisco 3504 Wireless Controller, Cisco 5520 Wireless Controller.