Skip to content

Channel Register

Cisco wireless products suffer multiple vulns

13 Apr 2007 00:34

These bugs can bite

SlashdotDiggdel.icio.usReddit
® [Printer] [Mobile]

Cisco Systems is reporting multiple vulnerabilities in three popular wireless products that can unleash all kinds of nastiness, including denials of service, privilege escalation, information disclosure and the ability to gain full administrative access.

The flaws reside in Cisco's Wireless Control System (WCS), Wireless LAN Controller and Lightweight Access Points.

Vulnerabilities in WCS include Fixed FTP Credentials for Location Backup, Account Group Privilege Escalation and Information Disclosure to Unauthenticated Users. Miscreants could exploit these flaws to write arbitrary files to the server that is hosting the WCS application, alter system files, and change an account group membership to gain full control of the WCS. Oh yeah, and all three can be exploited remotely.

The other two products suffer from five vulnerabilities, the most serious one affecting default SNMP community strings. That can also be exploited remotely and could allow an attacker to gain complete control of the device.

Cisco is advising administrators to apply fixes and workarounds. The advisories can be found here and here. ®

Track this type of story as a custom Atom/RSS feed or by email.
Previous Article Next Article
Whitepapers Jobs

Breaking Hardware News

triangular warning sign featuring exclamation mark

San Jose decides it's 'Visual Computing Week'

And just where does that leave National Bowling Week?

The heat rising from San Jose isn't merely an effect of a convention center full of GTX 280 cards being flipped on at once. Nvidia's decision to host its inaugural computing conference, Nvision 08, this week in the company's home town has fanned the flames of passion inside city officials.

Related Whitepapers