Cisco Access Point Web Interface Authorization Bypass Vulnerability
BID:18704
CVE-2006-3291 |Info
Cisco Access Point Web Interface Authorization Bypass Vulnerability
| Bugtraq ID: | 18704 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2006 12:00AM |
| Updated: | Sep 21 2006 07:56PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Cisco Wireless Mobile Interface Card (WMIC) 3200 Series Cisco Wireless Bridge 350 Cisco Wireless Bridge 1310 Cisco Wireless Access Point 350 Cisco Wireless Access Point 1410 Cisco Wireless Access Point 1240 Cisco Wireless Access Point 1200 Cisco Wireless Access Point 1130 Cisco Wireless Access Point 1100 Cisco IOS 12.3(8)JK Cisco IOS 12.3(8)JA1 Cisco IOS 12.3(8)JA |
| Not Vulnerable: | |
Discussion
Cisco Access Point Web Interface Authorization Bypass Vulnerability
Cisco Access Point web interface is prone to an authorization-bypass vulnerability.
This may permit an attacker to bypass the authentication mechanism and gain access to the web interface.
These issues affect only Cisco Access Points running Cisco IOS Software Release 12.3(8)JA or 12.3(8)JA1.
Cisco Access Point web interface is prone to an authorization-bypass vulnerability.
This may permit an attacker to bypass the authentication mechanism and gain access to the web interface.
These issues affect only Cisco Access Points running Cisco IOS Software Release 12.3(8)JA or 12.3(8)JA1.
Exploit / POC
Cisco Access Point Web Interface Authorization Bypass Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
Cisco Access Point Web Interface Authorization Bypass Vulnerability
Solution:
The vendor has released updates to address this issue. Please contact the vendor for details on obtaining the appropriate updates.
Solution:
The vendor has released updates to address this issue. Please contact the vendor for details on obtaining the appropriate updates.
References
Cisco Access Point Web Interface Authorization Bypass Vulnerability
References:
References: