Overview
A vulnerability in the Cisco Aironet 1100 Series Access Point may allow a remote attacker to discover valid accounts on the access point.
Description
Cisco describes the Aironet 1100 Series Access Point as, "an affordable and upgradable 802.11b wireless LAN (WLAN) solution, setting the enterprise standard for high performance, secure, manageable, and reliable WLANs." A vulnerability in this access point may allow a remote attacker to discover valid accounts on the device using brute-force techniques. For further technical information, please see the following documents: |
Impact
A remote attacker may be able to discover valid accounts on a vulnerable access point. |
Solution
Apply a vendor-supplied patch. |
Workarounds |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fsecur_c/fsaaa/index.htm
- http://www.cisco.com/pcgi-bin/Support/Bugtool/onebug.pl?bugid=CSCdz29724
- http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003002.htm
- http://www.cisco.com/warp/public/707/cisco-sn-20030724-ios-enum.shtml
- http://www.cisco.com/warp/public/cc/pd/witc/ps4570/
Acknowledgements
This vulnerability was discovered by Reda Zitouni of the Security Watch Team at VIGILANTe.
This document was written by Ian A Finlay.
Other Information
CVE IDs: | CVE-2003-0512 |
Severity Metric: | 4.80 |
Date Public: | 2003-07-28 |
Date First Published: | 2003-07-28 |
Date Last Updated: | 2003-07-29 13:21 UTC |
Document Revision: | 16 |