HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2014-0703

CVSS 10.0v2.0pub. 2014-03-06upd. 2026-05-06

Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the administrative HTTP server, which allows remote attackers to bypass intended access restrictions by connecting to an Aironet access point on which this server had been disabled ineffectively, aka Bug ID CSCuf66202.

CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
  • Cisco Wireless Lan Controller

    HW
    Cisco
    all versions
  • Cisco Wireless Lan Controller Software

    OS
    Cisco
    7.4.100.07.4.100.60
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Race Condition
CWE
References

Related vulnerabilities

CVE-2016-1363CRITICAL9.8PL ✓same product

Buffer overflow w Cisco WLC — zdalne wykonanie kodu przez HTTP

CVE-2015-6314CRITICAL9.8PL ✓same product

Cisco WLC — nieautoryzowana zmiana konfiguracji (Auth Bypass)

CVE-2024-20271HIGH8.6same product

A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated...

CVE-2022-20769HIGH7.4same product

A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software cou...

CVE-2021-1419HIGH7.8same product

A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a lo...