2016 m. sausio 15 d., penktadienis

Cisco Security Advisory: Cisco Aironet 1800 Series Access Point Default Static Account Credentials Vulnerability

Cisco Aironet 1800 Series Access Point Default Static Account Credentials Vulnerability

Advisory ID: cisco-sa-20160113-air

Revision 1.0

For Public Release 2016 January 13 16:00 UTC (GMT)

+-----------------------------------------------------------
----------

Summary
=======

A vulnerability in Cisco Aironet 1800 Series Access Point devices could
allow an unauthenticated, remote attacker to log in to the device by
using a default account that has a static password. By default, the
account does not have full administrative privileges.

The vulnerability is due to the presence of a default user account that
is created when the device is installed. An attacker could exploit this
vulnerability by logging in to the device by using the default account,
which could allow the attacker to gain unauthorized access to the device.

Cisco released software updates that address this vulnerability. There
are no workarounds that mitigate this vulnerability.

This advisory is available at the following link:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160113-air

Komentarų nėra:

Rašyti komentarą