ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

Cisco flaw threatens Wi-Fi networks

Joris Evers CNET News.com

Published: 03 Nov 2005 12:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security bug in Cisco's wireless LAN controllers could enable an attacker to send malicious traffic to a secured Wi-Fi network.

The problem affects large Wi-Fi networks, not the average home installation. It occurs when Cisco 1200, 1131 and 1240 series Wi-Fi access points are controlled by Cisco 2000 and 4400 series Airespace Wireless LAN Controllers, according to a security advisory released on Wednesday by the networking equipment maker.

Wi-Fi access points are the devices that let people connect to wireless service. Controllers are used by operators of large Wi-Fi networks, which typically include many access points, to centrally control functions such as security policies, intrusion prevention and radio frequency management.

The security problem affects only Wi-Fi installations that use the 2000 and 4400 controllers, Cisco said. Access points that do not link to those model systems are not affected, it added.

The access points, even when configured to handle encrypted network traffic only, may accept unencrypted incoming traffic, according to Cisco. An attacker could exploit the flaw to send malicious traffic to a wireless network that is designed to be secure, the company said. It could also allow unauthorised access.

A successful attack would require the attacker to use the hardware address — known as the Media Access Control number — of a device already authenticated to the network, mitigating the risk of an attack.

Cisco has a software update available for the WLAN controller to fix the vulnerability. The flaw is rated a "moderate risk" by the French Security Incident Response Team, FrSIRT, a security monitoring and research firm.

The news of the Wi-Fi security flaw comes a day after Cisco reported a security issue related to its intrusion prevention system, or IPS, security software. The problem exists because of an error in the configuration file of Cisco's Internetwork Operating System IPS, the company said in an advisory .

At risk are installations of the Cisco IPS configured by version 2.1 of the IPS Management Centre, Cisco said. The flaw might result in an incomplete analysis of network traffic secured by the Cisco IOS IPS device, which could allow some attacks to go unnoticed, according to Cisco. The flaw is also rated "moderate" risk by FrSIRT.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
70 out of 136 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Senior Systems Engineer - Windows Active Directory Cisco Lan/Wan VPN

Senior Systems Engineer - Windows 2000 2003 Active Directory Exchange Cisco Lan/Wan Cisco routers and switching. TCP/IP, Lan/Wan and VPN. Fantastic ...

Senior Server Analyst/ MCSE/ CCNA/ LAN/ WAN/AD/Exchange/WMWare 50k

Senior Server Analyst/ MCSE/ CCNA/ LAN/ WAN/ Active Directory/ Exchange/ Server2000/3/ IIS/ SQL/TCP/IP/ DNS/DHCP Leading Central London based ...

PC Installations - North London - IMMEDIATE START

A client based in North London are currently looking for a PC Installations Engineer for a 6 month contract. You will be performing PC installs with ...

On The Road Blog

Mobile Surfin’ USA

If everybody had a mobile – across the USA… OK, I’ll stop there. Actually, I’m not much of a Beach Boys fan. But betwixt a number of US-based events as I am, I think I’m more acutely... More

Post a comment

Gizmo Adds Business Enhancements and M...

Gizmo5 (formerly The Gizmo Project) has been my preferred program for IM text chat and audio calls (including PSTN calls worldwide) for quite some time now. The chat interface is clean... More

Post a comment

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment