Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

Cisco flaw threatens Wi-Fi networks

Joris Evers CNET News

Published: 03 Nov 2005 12:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security bug in Cisco's wireless LAN controllers could enable an attacker to send malicious traffic to a secured Wi-Fi network.

The problem affects large Wi-Fi networks, not the average home installation. It occurs when Cisco 1200, 1131 and 1240 series Wi-Fi access points are controlled by Cisco 2000 and 4400 series Airespace Wireless LAN Controllers, according to a security advisory released on Wednesday by the networking equipment maker.

Wi-Fi access points are the devices that let people connect to wireless service. Controllers are used by operators of large Wi-Fi networks, which typically include many access points, to centrally control functions such as security policies, intrusion prevention and radio frequency management.

The security problem affects only Wi-Fi installations that use the 2000 and 4400 controllers, Cisco said. Access points that do not link to those model systems are not affected, it added.

The access points, even when configured to handle encrypted network traffic only, may accept unencrypted incoming traffic, according to Cisco. An attacker could exploit the flaw to send malicious traffic to a wireless network that is designed to be secure, the company said. It could also allow unauthorised access.

A successful attack would require the attacker to use the hardware address — known as the Media Access Control number — of a device already authenticated to the network, mitigating the risk of an attack.

Cisco has a software update available for the WLAN controller to fix the vulnerability. The flaw is rated a "moderate risk" by the French Security Incident Response Team, FrSIRT, a security monitoring and research firm.

The news of the Wi-Fi security flaw comes a day after Cisco reported a security issue related to its intrusion prevention system, or IPS, security software. The problem exists because of an error in the configuration file of Cisco's Internetwork Operating System IPS, the company said in an advisory .

At risk are installations of the Cisco IPS configured by version 2.1 of the IPS Management Centre, Cisco said. The flaw might result in an incomplete analysis of network traffic secured by the Cisco IOS IPS device, which could allow some attacks to go unnoticed, according to Cisco. The flaw is also rated "moderate" risk by FrSIRT.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
71 out of 138 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

Author of Tech in Emergencies report a...

Q&A with Diane Coyle, co-author of the UN Foundation and Vodafone Foundation report New Technologies in Emergencies and Conflicts.What key advantages does use of social media and new... More

Post a comment

Mobile spells relief in Palestine

by Jacob Korenblum Whether you’re a foreign aid worker or a local community member--and whether you’re in Iraq or Guatemala—crisis events often look the same: High levels of confusion... More

Post a comment

Satellites to the rescue

By Einar Bjorgo Imagine a few years back – cell phones were reserved for a selected few, you could still keep up with your e-mail inbox and official correspondence would go via... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters