CVE-2019-15266: Cisco Wireless LAN Controller Path Traversal Vulnerability
A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the attacker to view system files that may contain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15266?
CVE-2019-15266 is a vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software that could allow an authenticated, local attacker to view system files that should be restricted.
How does CVE-2019-15266 occur?
CVE-2019-15266 occurs due to improper sanitization of user-supplied input in command-line parameters that describe filenames.
What is the severity of CVE-2019-15266?
The severity of CVE-2019-15266 is medium (4.4).
How can an attacker exploit CVE-2019-15266?
An attacker can exploit CVE-2019-15266 by authenticating locally and using the CLI to access system files that are meant to be restricted.
How can I fix CVE-2019-15266?
To fix CVE-2019-15266, Cisco recommends updating to a fixed software release.