6.5
CVSSv3

CVE-2018-0420

Published: 17/10/2018 Updated: 03/02/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an authenticated, remote malicious user to view sensitive information. The issue is due to improper sanitization of user-supplied input in HTTP request parameters that describe filenames and pathnames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the malicious user to view system files on the targeted device, which may contain sensitive information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco wireless lan controller software 8.2\\(151.0\\)

Vendor Advisories

A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an authenticated, remote attacker to view sensitive information The issue is due to improper sanitization of user-supplied input in HTTP request parameters that describe filenames and pathnames An attacker could exploit this vulnerability by using dir ...