Multiple Vendor Wireless Access Points Static WEP Key Authentication Bypass Vulnerability
BID:16068
Info
Multiple Vendor Wireless Access Points Static WEP Key Authentication Bypass Vulnerability
| Bugtraq ID: | 16068 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2005 12:00AM |
| Updated: | Dec 15 2005 12:00AM |
| Credit: | Discovered by Urmas Kahar and Tarmo Kaljumäe. |
| Vulnerable: |
Proxim Wireless AP-700 2.4.11 Proxim Wireless AP-600 2.4.11 Proxim Wireless AP-4000 2.4.11 Proxim Wireless AP-2000 2.4.11 Avaya Wireless AP-8 2.5 Avaya Wireless AP-8 Avaya Wireless AP-7 2.5 Avaya Wireless AP-7 Avaya Wireless AP-6 2.5.4 Avaya Wireless AP-6 2.5 Avaya Wireless AP-6 Avaya Wireless AP-5 2.5.4 Avaya Wireless AP-5 2.5 Avaya Wireless AP-5 Avaya Wireless AP-4 2.5.4 Avaya Wireless AP-4 2.5 Avaya Wireless AP-4 Avaya Wireless AP-3 2.5.4 Avaya Wireless AP-3 2.5 Avaya Wireless AP-3 |
| Not Vulnerable: |
Proxim Wireless AP-700 3.1 Proxim Wireless AP-600 2.5.5 Proxim Wireless AP-4000 3.1 Proxim Wireless AP-2000 2.5.5 Avaya Wireless AP-8 3.1 Avaya Wireless AP-7 3.1 Avaya Wireless AP-6 2.5.5 Avaya Wireless AP-5 2.5.5 Avaya Wireless AP-4 2.5.5 Avaya Wireless AP-3 2.5.5 |
Discussion
Multiple Vendor Wireless Access Points Static WEP Key Authentication Bypass Vulnerability
Multiple vendor wireless access points are prone to an authentication bypass vulnerability.
The vulnerability arises because the devices contain a hard coded static WEP key.
Avaya Wireless devices AP-3, AP-4, AP-5, AP-6, AP-7, and AP-8 are vulnerable to this issue. Proxim Wireless devices AP-600, AP-700, AP-2000 and AP-4000 are vulnerable as well.
Multiple vendor wireless access points are prone to an authentication bypass vulnerability.
The vulnerability arises because the devices contain a hard coded static WEP key.
Avaya Wireless devices AP-3, AP-4, AP-5, AP-6, AP-7, and AP-8 are vulnerable to this issue. Proxim Wireless devices AP-600, AP-700, AP-2000 and AP-4000 are vulnerable as well.
Exploit / POC
Multiple Vendor Wireless Access Points Static WEP Key Authentication Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Multiple Vendor Wireless Access Points Static WEP Key Authentication Bypass Vulnerability
Solution:
Avaya has released advisory ASA-2005-233 to address this issue in affected products. Please see references for more information.
Proxim has released advisory ASA-2005-3253 to address this issue in affected products. Please see references for more information.
Solution:
Avaya has released advisory ASA-2005-233 to address this issue in affected products. Please see references for more information.
Proxim has released advisory ASA-2005-3253 to address this issue in affected products. Please see references for more information.
References
Multiple Vendor Wireless Access Points Static WEP Key Authentication Bypass Vulnerability
References:
References: