Cisco warns of Wi-Fi vulnerability

Hard-coded login data in two wireless Lan products could give attackers complete control

Steve Hill

Cisco has issued a security warning for two products used to manage wireless local area network (Lan) and e-business services in data centres.

The company said that a username and password coded into all releases of the Wireless LAN Solution Engine (WLSE) and Hosting Solution Engine (HSE) software could give attackers complete control of the devices.

Advertisement

The warning states: "A user who logs in using this username has complete control of the device. This username cannot be disabled. There is no workaround."

CiscoWorks WLSE provides centralised management for the Cisco wireless Lan infrastructure. It unifies the other components in the solution and actively employs them to provide continual 'Air/RF' monitoring, network security and optimisation.

It also assists network managers by automating and simplifying mass configuration deployment, fault monitoring and alerting.

HSE monitors and activates a variety of e-business services in Cisco-powered data centres.

The warning adds: "Any user who logs in using this username has complete control of the device. One can add new users or modify details of the existing users, and change the device's configuration."

The company cautioned that this could result in system-wide outages, long-term loss of information confidentiality and integrity, and yield denial of service.

Cisco said it was unaware of any attacks that use the hard-coded login information, but has advised customers to install the appropriate software patch.

For more information click here.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Open source vulnerability database opens

Public access one-stop shop for data on hardware and software flaws

Malicious code targets earlier Cisco flaws

Customers advised to upgrade software or provide workarounds for vulnerabilities

Big two are up for integration

IBM and Cisco join forces to address network security

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file...

Dell Adamo XPS

Dell launches ultra-thin Adamo XPS

World's thinnest laptop will be available by Christmas

Top 10 articles, 6 November 2009

The worst Microsoft products of all time, and a USB...

Iain Thomson

Pirate Bay shutdown could be inspiring online militancy

Recent Swedish attacks raise worrying possibility

Primary Navigation