First published: Mon Aug 09 2010(Updated: )
Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 does not use an adequate message-digest algorithm for a self-signed certificate, which allows remote attackers to bypass intended access restrictions via vectors involving collisions, aka Bug ID CSCtd67660.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Wireless Network Solution | =7.0 | |
Cisco Unified Wireless Network Solution | =7.0.98.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2978 is classified as a high severity vulnerability due to its potential to allow unauthorized remote access.
To fix CVE-2010-2978, upgrade to Cisco Unified Wireless Network Solution version 7.0.98.0 or later.
CVE-2010-2978 affects Cisco Unified Wireless Network Solution versions before 7.0.98.0.
Yes, CVE-2010-2978 can be exploited by remote attackers without requiring authentication.
The primary issue with CVE-2010-2978 is the use of an inadequate message-digest algorithm for self-signed certificates, allowing for collision attacks.