CVE-2022-20695 is a critical authentication bypass vulnerability in Cisco Wireless LAN Controller (WLC) Software, stemming from improper password validation. An unauthenticated, remote attacker can exploit this by crafting specific credentials to log in as an administrator, gaining full control over the device. While requiring a non-default configuration, its CVSS score of 10.0 highlights the severe impact of complete compromise. Currently, there is no public exploit code, nor is it listed in CISA's KEV catalog, though it has garnered significant media and community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:cisco:wireless_lan_controller_8.10.151.0:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:cisco:wireless_lan_controller_8.10.162.0:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.