Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-15266

Опубликовано: 16 окт. 2019
Источник: nvd
CVSS3: 4.4
CVSS3: 4.4
CVSS2: 2.1
EPSS Низкий

Описание

A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the attacker to view system files that may contain sensitive information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:wireless_lan_controller_software:*:*:*:*:*:*:*:*
Версия до 8.10 (исключая)

EPSS

Процентиль: 26%
0.0009
Низкий

4.4 Medium

CVSS3

4.4 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 4.4
github
больше 3 лет назад

A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the attacker to view system files that may contain sensitive information.

CVSS3: 4.4
fstec
больше 6 лет назад

Уязвимость компонента CLI микропрограммного обеспечения контроллеров беспроводного доступа Cisco Wireless LAN Controller (WLC), позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 26%
0.0009
Низкий

4.4 Medium

CVSS3

4.4 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-22
CWE-22