OSVDB ID: 34133

Title: Cisco Aironet Lightweight Access Points Persistent Admin Password

Info

Disclosure

Apr 12, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

By default, Aironet 1000 & 1500 Series Lightweight Access Points install with a default password. This allows attackers with console access to trivially access the system.

Classification

Location: Physical Access Required
Attack Type: Authentication Management
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 3.2.185.0 or 4.0.206.0 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Cisco Systems, Inc.

Aironet 1000 Series Lightweight Access Point

4.0.179.8

Aironet 1500 Series Lightweight Access Point

3.2.171.6

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/34133