In addition Cisco said the WCS and the Lightweight Access Points contain multiple vulnerabilities that could result in a denial of service attack.
In a Cisco advisory
Requires Free Membership to View
Among some of the issues, Cisco said an authentication system within the WCS contains a privilege escalation vulnerability that allows any user with a valid user name and password to change their account group membership.
If the WCS is configured to back up the data stored on the Cisco Wireless Location Appliance via FTP. An attacker can use the credentials with other properties of the FTP server to read and write to arbitrary files on the server hosting the WCS application. The attacker could alter system files and compromise the server.
Several directories within the WCS page hierarchy are not password protected and could be accessed by an unauthenticated user.
Security Management Strategies for the CIO
Join the conversationComment
Share
Comments
Results
Contribute to the conversation