Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability

BID:15272

Info

Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability

Bugtraq ID: 15272
Class: Access Validation Error
CVE:
Remote: Yes
Local: No
Published: Nov 02 2005 12:00AM
Updated: Nov 02 2005 12:00AM
Credit: This issue was announced by the vendor.
Vulnerable: Cisco 4000 Series Airespace Wireless LAN Controller 3.1.59 .24
Cisco 2000 Series Airespace Wireless LAN Controller 3.1.59 .24
Cisco 1240 Series Access Point
Cisco 1200 Series Access Point
Cisco 1131 Series Access Point
Not Vulnerable:

Discussion

Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability

Cisco Airespace WLAN (Wireless LAN) devices are prone to an issue that may permit unauthorized parties to access a secure network.

This issue can occur when Cisco access points are configured to run in Lightweight Access Point Protocol (LWAPP) mode.

This vulnerability may allow unauthorized parties to send unencrypted network packets to a secure network by spoofing the MAC address of another host that has already authenticated. This may bypass the security of the wireless network as it may permit unauthorized access by hosts that have not authenticated.

Exploit / POC

Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability

It is likely that this issue could be exploited with a publicly available packet crafting or MAC address spoofing utility.

Solution / Fix

Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability

Solution:
Cisco has released software upgrades to address this issue. These upgrades must be applied to affected WLAN controllers as the access points will download their software from the controllers. Please see the attached Cisco advisory for further information.

References

Cisco Airespace WLAN Controller Unauthorized Network Access Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report