CVE-2023-20003
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login authentication. This vulnerability is due to a logic error with the social login implementation. An attacker could exploit this vulnerability by attempting to authenticate to an affected device. A successful exploit could allow the attacker to access the Guest Portal without authentication.
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.8.1.0 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 140ac Access Point | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.8.1.0 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 141acm | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.8.1.0 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 142acm | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.8.1.0 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 143acm | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 151axm | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.8.1.0 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 145ac Access Point | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.4.2 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 150ax Access Point | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.8.1.0 |
| Running on/with | Platform Versions |
|---|---|
Cisco Business 240ac Access Point | All versions |
Related CWEs
CWE-288
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
CWE-306
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.