CVE-2010-2975: Infoleak
Published Aug 9, 2010
·Updated
Cisco Unified Wireless Network (UWN) Solution 7.x through 7.0.98.0 does not properly handle multiple SSH sessions, which allows physically proximate attackers to read a password, related to an "arrow key failure," aka Bug ID CSCtg51544.
Affected Software
2 affected components
Cisco Unified Wireless Network Solution Software=7.0
Cisco Unified Wireless Network Solution Software=7.0.98.0
Event History
Aug 9, 2010
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2975?
CVE-2010-2975 is considered a medium severity vulnerability.
2
How do I fix CVE-2010-2975?
To fix CVE-2010-2975, upgrade to a version of Cisco Unified Wireless Network Solution later than 7.0.98.0.
3
What exploits exist for CVE-2010-2975?
Exploits for CVE-2010-2975 could allow an attacker with physical access to read sensitive information, such as passwords.
4
Who is affected by CVE-2010-2975?
Users of Cisco Unified Wireless Network Solution versions 7.x through 7.0.98.0 are affected by CVE-2010-2975.
5
What is the nature of the vulnerability in CVE-2010-2975?
CVE-2010-2975 is caused by improper handling of multiple SSH sessions which leads to potential security risks.