CVE-2018-0417 describes a vulnerability in Cisco Wireless LAN Controller (WLC) Software that allows an authenticated, local attacker to gain elevated privileges through incorrect parsing of a TACACS attribute. The vulnerability, rated 7.8 HIGH, permits the creation of administrative user accounts and execution of unauthorized commands, despite requiring local access and prior authentication. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.7\(1.115\)CPE matchmatch criteria | cpe:2.3:o:cisco:wireless_lan_controller_software:8.7\(1.115\):*:*:*:*:*:*:* | ||
>= 8.4, < 8.5.131.0CPE matchmatch criteria | cpe:2.3:o:cisco:wireless_lan_controller:*:*:*:*:*:*:*:* | ||
< 8.2.170.0CPE matchmatch criteria | cpe:2.3:o:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:* | ||
>= 8.6, < 8.7.102.0CPE matchmatch criteria | cpe:2.3:o:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.