Cisco Aironet Access Point Wired Equivalent Privacy Key Disclosure Vulnerability
BID:9143
Info
Cisco Aironet Access Point Wired Equivalent Privacy Key Disclosure Vulnerability
| Bugtraq ID: | 9143 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 02 2003 12:00AM |
| Updated: | Dec 02 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Bill Van Devender. |
| Vulnerable: |
Cisco IOS 12.2(8)JA Cisco IOS 12.2(11)JA1 Cisco IOS 12.2(11)JA |
| Not Vulnerable: |
Cisco IOS 12.2(13)JA1 |
Discussion
Cisco Aironet Access Point Wired Equivalent Privacy Key Disclosure Vulnerability
Cisco Aironet Access Points that are running Cisco IOS have been reported prone to an information disclosure vulnerability that could lead to the disclosure of wired equivalent privacy (WEP) keys.
The issue has been reported to exist if the 'snmp-server enable traps wlan-wep' command has been set. The issue presents itself because when this functionality is enabled the Cisco Aironet Access Point will send the WEP key in a plain text format to the simple network management protocol server.
Cisco Aironet Access Points that are running Cisco IOS have been reported prone to an information disclosure vulnerability that could lead to the disclosure of wired equivalent privacy (WEP) keys.
The issue has been reported to exist if the 'snmp-server enable traps wlan-wep' command has been set. The issue presents itself because when this functionality is enabled the Cisco Aironet Access Point will send the WEP key in a plain text format to the simple network management protocol server.
Exploit / POC
Cisco Aironet Access Point Wired Equivalent Privacy Key Disclosure Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Cisco Aironet Access Point Wired Equivalent Privacy Key Disclosure Vulnerability
Solution:
Cisco has released IOS version 12.2(13)JA1 to address this issue. Users are advised to contact the vendor to obtain fixes.
Solution:
Cisco has released IOS version 12.2(13)JA1 to address this issue. Users are advised to contact the vendor to obtain fixes.
References
Cisco Aironet Access Point Wired Equivalent Privacy Key Disclosure Vulnerability
References:
References:
- Cisco Call Manager Express (Cisco Systems)
- Cisco IOS Software (Cisco Systems)