You are here
Home > Preporuke > Ranjivosti Cisco Aironet 1800 Series Access Point uređaja

Ranjivosti Cisco Aironet 1800 Series Access Point uređaja

  • Detalji os-a: CIS
  • Važnost: IMP
  • Operativni sustavi: O
  • Kategorije: CIS

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

Cisco Aironet 1800 Series Access Point Default Static Account Credentials Vulnerability

Advisory ID: cisco-sa-20160113-air

Revision 1.0

For Public Release 2016 January 13 16:00 UTC (GMT)

+———————————————————————

Summary
=======

A vulnerability in Cisco Aironet 1800 Series Access Point devices could
allow an unauthenticated, remote attacker to log in to the device by
using a default account that has a static password. By default, the
account does not have full administrative privileges.

The vulnerability is due to the presence of a default user account that
is created when the device is installed. An attacker could exploit this
vulnerability by logging in to the device by using the default account,
which could allow the attacker to gain unauthorized access to the device.

Cisco released software updates that address this vulnerability. There
are no workarounds that mitigate this vulnerability.

This advisory is available at the following link:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160113-air
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.5 (SunOS)

iQIVAwUBVosVAIpI1I6i1Mx3AQJCpRAAtWYXszbCReZekmWZIvb18lJvLmVqpNq+
KuUMPyowV1rWAmPuL6e3vzLysyigA1wL8VGes0Y9xwjQH7RC0SOxBll9A/WtcBsr
JQjDn8VwvDBU0Z7GjrRKnjqYOY8M6l6f8OKn6zAYLUmyhpnpR95s9srXyjzgXz5A
jfyLvUZhD+/RAnQlvqvBPbIVBUAXAWjFBWdjIR39u+6yRPhiYEobMNM8DmafRiVc
H3nenqqBmKl8JJwZsGAneLIErMmfVHpTefqkgIX8Y9yBqMLbfH843QRzs5RpGPD9
5RmVCdi1UP6yeQV2kHUacMXXu/GlYfWEZUVvgRmtONdO00nQ532zhpPtxJ3w0UpF
9Z8qnjKwZN9BIySeatZ+Lvq6MQtbGEwZ9lxlv8NXDy29aInn1/MLE20fZwPkfKZF
xZ4uvDPP0b0KII8kO/ALso/evE0Pv/wv+hblevEYBfb+T3dt6f9e0qHS7OTYTccr
XUEllOsMFRAAabtgO1XIuh38q+Waf2hB8EWYagS0HT9KAOsd0pR86X9iz/BbpnvC
TtDVlIxSJ/RQBYCbfkKbOdLEUvkb3vvJvSFu7J2qoRBXmP1Bu+ubovKrZpBOaSr1
jDT8xDU326MP2uAxAF8lVXD7lDJ6jK4NUM1KN3maW3LYqNT2fBEHX1VCvZHGNm4n
eDaroWHF4MU=
=WE2t
—–END PGP SIGNATURE—–
_______________________________________________
cust-security-announce mailing list
cust-security-announce@cisco.com
To unsubscribe, send the command “unsubscribe” in the subject of your message to cust-security-announce-leave@cisco.com

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

Cisco Aironet 1800 Series Access Point Denial of Service Vulnerability

Advisory ID: cisco-sa-20160113-aironet

Revision 1.0

For Public Release 2016 January 13 16:00 UTC (GMT)

+———————————————————————

Summary
=======

A vulnerability in the IP ingress packet handler of Cisco Aironet 1800
Series Access Point devices could allow an unauthenticated, remote
attacker to cause a complete denial of service (DoS) condition.

The vulnerability is due to improper input validation of IP packet
headers. An attacker could exploit this vulnerability by sending a
crafted IP packet to an affected device. An successful exploit could
allow the attacker to cause the device to reload unexpectedly.

Cisco has released software updates that address this vulnerability.
There are no workarounds that mitigate this vulnerability.

This advisory is available at the following link:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160113-aironet
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.5 (SunOS)

iQIVAwUBVosVKYpI1I6i1Mx3AQLKrBAAwa5s+vBxe9L2Pf4SnfY8PGQWAJmbVf+p
V21gGG5NX5A9F9L6SVhRSyyRYAJjtvuY5H0hxkL9HCN6UT+31vI+unQdUinDXWZL
HbV4siEiwFA0XhdY+i5O8GE7jxdZjXROH5m9z4n0v2s4e2YDSUGYcb3UmtmXuWgn
iirpBBpWIM8cEELZ6YXhPGpG6xKCDyrYOndj7jN5orJNpBvnSKe82vYBYqiljL4d
A4iiMTfqAybFnf9V4sha7/vXFnCqihpAm7Hy1RiVdlIRclhqEsFPMkmPTdJ+3rkV
5VPmGJmNQQBFtm4bOstSETCAIeu/NFd+xCo2/pOvPHctUEv3b+qDplyeXK7EmZ4I
9L58U8j+7mc9LDzyx4naOzmFh1N0PIeSsgFXL7BXby+UyBmHeaNOdTc0gzwb5Nqn
CTgA93jmgcs9EEXe6wFLMZ0Hd8EGMUcCTELIh4Vt71TdKo4hCvaablyCpNIuDb6m
aA+V1/Vg1SpOndjuj1r2YAHNoXo3dNNj1TBYEl8MosRGOSJNMUdjjsghyKNbFCCJ
980xcN9R70LEMhhiJszfKXEPa/yknlIN12FN2eT84inGW19R/hRyMCPv8FQfeTwk
aTWI4M0Qo+hQTwCiFCJpOgN7VTvd5D1K9f/bQrW9+5zXVz73OM0gaRK/lZHpd4za
RNHmaSb075s=
=lY3/
—–END PGP SIGNATURE—–
_______________________________________________
cust-security-announce mailing list
cust-security-announce@cisco.com
To unsubscribe, send the command “unsubscribe” in the subject of your message to cust-security-announce-leave@cisco.com

AutorTomislav Protega
Cert idNCERT-REF-2016-01-0015-ADV
ID izvornikacisco-sa-20160113-air cisco-sa-20160113-aironet
Proizvodair cisco-sa-20160113-aironet
Izvorhttp://www.cisco.com
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa isc-dhcp

Otkriven je sigurnosni nedostatak u programskom paketu isc-dhcp za Ubuntu. Otkriveni nedostatak potencijalnim napadačima omogućuje izvođenje napada uskraćivanjem usluge slanjem...

Close