Cisco has released a vulnerability disclosure for their Wireless Access Points: http://www.cisco.com/warp The vuln is in the web interface for the APs and could allow wiping of the security config and access to the administrative interface without authentication. To quote Cisco: A vulnerability exists in the access point web-browser interface when Security > Admin Access is changed from Default Authentication (Global Password) to Local User List Only (Individual Passwords). This results in the access point being re-configured with no security, either Global Password or Individual Passwords, enabled. This allows for open access to the access point via the web-browser interface or via the console port with no validation of user credentials. The following access points are affected if running Cisco IOSŪ Software Release 12.3(8)JA or 12.3(8)JA1 and are configured for web-interface management:
|
Toby 68 Posts Jun 29th 2006 |
Thread locked Subscribe |
Jun 29th 2006 1 decade ago |
Sign Up for Free or Log In to start participating in the conversation!