Feeds

Cisco Wi-Fi kit in minor security flap

WEP schlep

  • alert
  • submit to reddit

Top 5 reasons to deploy VMware with Tegile

Cisco yesterday warned of a security vulnerability in the software running on its popular line of Aironet wireless LAN access points.

Under certain conditions, Aironet Access Points running Cisco IOS software will send static Wired Equivalent Privacy (WEP) keys to in clear text to Simple Network Management Protocol (SNMP) server every time a key is changed or AP rebooted.

Not good - but the relevant enable traps wlan-wep command is disabled by default on Cisco's hardware, so the flaw is not particularly high risk.

Network admins are advised to disable the command as a workaround.

Any dynamically set WEP key will not be disclosed by the vulnerability.

The vulnerability was discovered by security researcher Bill Van Devender. Cisco is not aware of any malicious exploitation of the software flaw.

Cisco Aironet Access Point 1100, 1200 and 1400 series running Cisco IOS software are potentially affected. The Cisco AP 350 running Cisco IOS software is not affected, nor are Aironet Access Points running VxWorks based Operating System software.

The networking giant is offering free software upgrades designed to remedy this vulnerability for all affected customers.

More info in Cisco's advisory here. ®

Related Stories

Snag in next-gen Wi-Fi security unearthed
New WPA wireless security on its way
WLAN security is still work in progress
Tool dumbs down wireless hacking (AirSnort - WEP cracking tool)
Cisco looks for WLAN boost

Related Products
Great prices on Wi-Fi kit in the The Reg wireless store

Security for virtualized datacentres

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
How to simplify SSL certificate management
Simple steps to take control of SSL certificates across the enterprise, and recommendations centralizing certificate management throughout their lifecycle.