CVE-2018-5797: High severity Extremenetworks Extremewireless Wing vulnerability
An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smintencrypt Hardcoded AES Key that can be used for packet decryption (obtaining cleartext credentials) by an attacker who has access to a wired port.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-5797?
CVE-2018-5797 is a vulnerability discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3.
What is the severity of CVE-2018-5797?
The severity of CVE-2018-5797 is high with a CVSS score of 7.5.
How can an attacker exploit CVE-2018-5797?
An attacker with access to a wired port can exploit CVE-2018-5797 to obtain cleartext credentials by using the hardcoded AES key for packet decryption.
Which software versions are affected by CVE-2018-5797?
ExtremeWireless WiNG 5.x versions before 5.8.6.9 and 5.9.x versions before 5.9.1.3 are affected by CVE-2018-5797.
Where can I find more information about CVE-2018-5797?
You can find more information about CVE-2018-5797 in the Extreme Networks Vulnerability Notice VN-2018-003 at the following link: [https://gtacknowledge.extremenetworks.com/articles/Vulnerability_Notice/VN-2018-003]