On TechRepublic: FREE download: Social networking policy
BNET Business Network:
BNET
TechRepublic
ZDNet

February 4th, 2009

Cisco warning: Serious flaws in Wireless LAN controllers

Posted by Ryan Naraine @ 9:53 am

Categories: Arbitrary Code Execution, Cisco, Complex Attacks, Denial of Service (DoS), Responsible disclosure, Vulnerability research, Web 2.0, Zero-day attacks

Tags: Cisco Catalyst, Flaw, WLAN, IP, Cisco Systems Inc., Wireless, LANs, Wireless LANs, Wi-Fi, Wireless And Mobility

Routing and switching giant Cisco has released an alert to warn of multiple security flaws in some of its Wireless LAN controllers.

The company documented at least four vulnerabilities that could lead to denial-of-service or privilege escalation attacks.  Affected product lines include Cisco Wireless LAN Controllers (WLCs), Cisco Catalyst 6500 Wireless Services Modules (WiSMs), and Cisco Catalyst 3750 Integrated Wireless LAN Controllers.

The skinny:

  • CVE-2009-0058: Web authentication is a Layer 3 security feature that causes the
    controller to drop IP traffic (except DHCP and DNS related packets) from a
    particular client until that client has correctly supplied a valid username and
    password.
  • CVE-2009-0059: An attacker may cause a device reload when sending a malformed post
    to the web authentication “login.html” page.
  • CVE-2009-0061: Affected Cisco WLC, WiSM and Catalyst 3750 Wireless LAN Controller
    models are vulnerable to a DoS condition that is triggered by the receipt of
    certain IP packets. Upon receiving these IP packets, the affected device may
    become unresponsive and require a reboot to recover.
  • CVE-2009-0062: A privilege escalation vulnerability exists only in WLC software
    version 4.2.173.0, and could allow a restricted user (i.e., Lobby Admin) to
    gain full administrative rights on the affected system.

One of these flaws carry a CVSS Base Score of 9.0, meaning it should be treated as a “high priority” update.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 2 Talkback(s)
RE: Cisco warning: Serious flaws in Wireless LAN controllers
Ryan;
I'm not a fan of 'I know something you don't know'. Please don't use phrases such as "One of these flaws....".

Be explicit for your readers, such as "CVE-2009 blah blah blah, has a high priority rating".

Regards,
Nik... (Read the rest)
Posted by: grumpie@... Posted on: 02/10/09 You are currently: a Guest | | Terms of Use
Are other products involved?  TheBrass | 02/10/09
RE: Cisco warning: Serious flaws in Wireless LAN controllers  grumpie@... | 02/10/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here