cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2523
Views
0
Helpful
3
Replies

CVE-2020-11022 on WLC 8.10.130

richard.greene1
Level 1
Level 1

JQUERY <3.5

Our security team has informed us that the 3504 running 8.10.130 is showing as vulnerable for the issue identified in CVE-2020-11022

 

In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

3 Replies 3

Leo Laohoo
Hall of Fame
Hall of Fame

From what I can read, CVE-2020-11022/CVE-2020-11023 only affects Cisco Unified Presence, UCSM and APIC. 

I don't see anything mentioning about AireOS.

Interestingly I found this bug: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu12372
opened for CVE-2015-9251, CVE-2019-11358 but right at the end of the notes says: Related : CVE-2020-11022
I think you need to contact Cisco PSIRT or TAC to confirm whether this means AireOS is affected by CVE-2020-11022 or not (and ask them to update the bug notes to clarify).
Either way it's fixed in 8.10(139.14) so not in a public release yet and it's classified as Severity: 6 Enhancement so clearly not considered to be high risk which I guess means you can't do much harm with it on AireOS.

we have the same issue on VWLC and CT2500 both with 8.5(160.0) version.

Review Cisco Networking products for a $25 gift card