CVE-2024-20510

CVSS 3.1 Score 9.3 of 10 (high)

Details

Published Sep 25, 2024
Updated: Oct 3, 2024
CWE ID 863

Summary

CVE-2024-20510 is a vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers. This issue allows an unauthenticated, adjacent attacker to bypass the pre-authentication access control list (ACL), which could grant access to network resources before user authentication. The vulnerability is due to a logic error in the handling of the pre-authentication ACL received from the authentication, authorization, and accounting (AAA) server. An attacker could exploit this flaw by connecting to a wireless network that is configured for CWA and sending malicious traffic through an affected device. Successful exploitation could enable the attacker to bypass the configured ACL protections on the affected device, potentially gaining unauthorized access to trusted networks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share