Home > Security News > Cisco urges Wireless Control System upgrade
Security News:
EMAIL THIS LICENSING & REPRINTS

Cisco urges Wireless Control System upgrade

By SearchSecurity.com Staff
13 Apr 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Cisco's Wireless Control System (WCS) contains a vulnerability that could allow an attacker to gain full administrative control of WCS.

In addition Cisco said the WCS and the Lightweight Access Points contain multiple vulnerabilities that could result in a denial of service attack.

In a Cisco advisory issued Thursday, the vendor said there are no known workarounds for these vulnerabilities. Versions of the WCS prior to 4.0.96.0 are affected by the f;aws. Cisco has released free software updates to fix the flaws and is urging customers to upgrade to version 4.0.96.0.

Among some of the issues, Cisco said an authentication system within the WCS contains a privilege escalation vulnerability that allows any user with a valid user name and password to change their account group membership.

If the WCS is configured to back up the data stored on the Cisco Wireless Location Appliance via FTP. An attacker can use the credentials with other properties of the FTP server to read and write to arbitrary files on the server hosting the WCS application. The attacker could alter system files and compromise the server.

Several directories within the WCS page hierarchy are not password protected and could be accessed by an unauthenticated user.

Sound Off! -   Be the first to post a message to Sound Off!


Tags: Wireless LAN ArchitectureWireless Access ControlVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts