Lucene search

K
cveCiscoCVE-2015-6336
HistoryJan 15, 2016 - 3:59 a.m.

CVE-2015-6336

2016-01-1503:59:08
CWE-255
cisco
web.nvd.nist.gov
24
cisco
aironet 1800
default account
cve-2015-6336
nvd
vulnerability
security issue

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

7.1

Confidence

High

EPSS

0.002

Percentile

54.2%

Cisco Aironet 1800 devices with software 7.2, 7.3, 7.4, 8.1(112.3), 8.1(112.4), and 8.1(15.14) have a default account, which makes it easier for remote attackers to obtain access via unspecified vectors, aka Bug ID CSCuw58062.

Affected configurations

Nvd
Node
ciscoaironet_access_point_softwareMatch7.2_base
OR
ciscoaironet_access_point_softwareMatch7.3_base
OR
ciscoaironet_access_point_softwareMatch7.4_base
OR
ciscoaironet_access_point_softwareMatch8.1\(15.14\)
OR
ciscoaironet_access_point_softwareMatch8.1\(112.3\)
OR
ciscoaironet_access_point_softwareMatch8.1\(112.4\)
AND
ciscoaironet_1830e
OR
ciscoaironet_1830i
OR
ciscoaironet_1850e
OR
ciscoaironet_1850i
VendorProductVersionCPE
ciscoaironet_access_point_software7.2_basecpe:2.3:o:cisco:aironet_access_point_software:7.2_base:*:*:*:*:*:*:*
ciscoaironet_access_point_software7.3_basecpe:2.3:o:cisco:aironet_access_point_software:7.3_base:*:*:*:*:*:*:*
ciscoaironet_access_point_software7.4_basecpe:2.3:o:cisco:aironet_access_point_software:7.4_base:*:*:*:*:*:*:*
ciscoaironet_access_point_software8.1(15.14)cpe:2.3:o:cisco:aironet_access_point_software:8.1\(15.14\):*:*:*:*:*:*:*
ciscoaironet_access_point_software8.1(112.3)cpe:2.3:o:cisco:aironet_access_point_software:8.1\(112.3\):*:*:*:*:*:*:*
ciscoaironet_access_point_software8.1(112.4)cpe:2.3:o:cisco:aironet_access_point_software:8.1\(112.4\):*:*:*:*:*:*:*
ciscoaironet_1830e*cpe:2.3:h:cisco:aironet_1830e:*:*:*:*:*:*:*:*
ciscoaironet_1830i*cpe:2.3:h:cisco:aironet_1830i:*:*:*:*:*:*:*:*
ciscoaironet_1850e*cpe:2.3:h:cisco:aironet_1850e:*:*:*:*:*:*:*:*
ciscoaironet_1850i*cpe:2.3:h:cisco:aironet_1850i:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

7.1

Confidence

High

EPSS

0.002

Percentile

54.2%

Related for CVE-2015-6336