Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-0062


Unspecified vulnerability in the Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.2.173.0 allows remote authenticated users to gain privileges via unknown vectors, as demonstrated by escalation from the (1) Lobby Admin and (2) Local Management User privilege levels.


Published

2009-02-05T00:30:00.327

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware cisco catalyst_3750_series_integrated_wireless_lan_controller 4.2 Yes
Hardware cisco catalyst_3750_series_integrated_wireless_lan_controller 4.2.173.0 Yes
Hardware cisco catalyst_6500_wireless_services_modules 4.2 Yes
Hardware cisco catalyst_6500_wireless_services_modules 4.2.173.0 Yes
Operating System cisco wireless_lan_controller_software 4.2 Yes
Operating System cisco wireless_lan_controller_software 4.2.173.0 Yes

References