Vulnslist

find the latest Cisco vulnerabilities

Cisco Aironet 1800 Series Access Point Default Static Account Credentials Vulnerability

cisco-sa-20160113-air · High · Published · Updated

A vulnerability in Cisco Aironet 1800 Series Access Point devices could allow an unauthenticated, remote attacker to log in to the device by using a default account that has a static password. By default, the account does not have full administrative privileges. The vulnerability is due to the presence of a default user account that is created when the device is installed. An attacker could exploit this vulnerability by logging in to the device by using the default account, which could allow the attacker to gain unauthorized access to the device. Cisco released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160113-air

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2015-6336
Cisco Bug IDsCSCuw58062
CVSS ScoreBase 7.5
Base 7.5 AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C
Product Names From Source
Cisco Aironet Access Point Software

Related Products

Product CVE Evidence
Cisco Nexus Dashboard CVE-2015-6336 Cisco OpenVuln
Cisco Application Centric Infrastructure Virtual Edge CVE-2015-6336 Cisco OpenVuln
Cisco Aironet Access Point Software CVE-2015-6336 Cisco OpenVuln