Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability
BID:15272
Info
Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability
| Bugtraq ID: | 15272 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2005 12:00AM |
| Updated: | Nov 02 2005 12:00AM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
Cisco 4000 Series Airespace Wireless LAN Controller 3.1.59 .24 Cisco 2000 Series Airespace Wireless LAN Controller 3.1.59 .24 Cisco 1240 Series Access Point Cisco 1200 Series Access Point Cisco 1131 Series Access Point |
| Not Vulnerable: | |
Discussion
Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability
Cisco Airespace WLAN (Wireless LAN) devices are prone to an issue that may permit unauthorized parties to access a secure network.
This issue can occur when Cisco access points are configured to run in Lightweight Access Point Protocol (LWAPP) mode.
This vulnerability may allow unauthorized parties to send unencrypted network packets to a secure network by spoofing the MAC address of another host that has already authenticated. This may bypass the security of the wireless network as it may permit unauthorized access by hosts that have not authenticated.
Cisco Airespace WLAN (Wireless LAN) devices are prone to an issue that may permit unauthorized parties to access a secure network.
This issue can occur when Cisco access points are configured to run in Lightweight Access Point Protocol (LWAPP) mode.
This vulnerability may allow unauthorized parties to send unencrypted network packets to a secure network by spoofing the MAC address of another host that has already authenticated. This may bypass the security of the wireless network as it may permit unauthorized access by hosts that have not authenticated.
Exploit / POC
Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability
It is likely that this issue could be exploited with a publicly available packet crafting or MAC address spoofing utility.
It is likely that this issue could be exploited with a publicly available packet crafting or MAC address spoofing utility.
Solution / Fix
Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability
Solution:
Cisco has released software upgrades to address this issue. These upgrades must be applied to affected WLAN controllers as the access points will download their software from the controllers. Please see the attached Cisco advisory for further information.
Solution:
Cisco has released software upgrades to address this issue. These upgrades must be applied to affected WLAN controllers as the access points will download their software from the controllers. Please see the attached Cisco advisory for further information.
References
Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability
References:
References: