SSH Access Vulnerability in Cisco Aironet Access Points
CVE-2018-0226
7.5HIGH
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 2 May 2018
What is CVE-2018-0226?
The vulnerability arises from the incorrect management of SSH user accounts for Cisco Aironet 1800, 2800, and 3800 Series Access Points running Cisco Mobility Express Software. An authenticated attacker can exploit this weakness to gain elevated privileges. Specifically, if an administrator adds user accounts improperly, the default SSH user account configuration allows attackers with valid credentials to authenticate to the access point using a privilege escalation method. This could lead to unauthorized administrative access and possible control over the network device.
Affected Version(s)
Cisco Aironet 1800, 2800, and 3800 Series Access Points Cisco Aironet 1800, 2800, and 3800 Series Access Points