Cisco Reports WLAN Vulnerabilities

Cisco Reports WLAN Vulnerabilities

Written By
Carmen Nobel
Carmen Nobel
Nov 2, 2005
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Certain wireless LAN access points from Cisco Systems Inc. are vulnerable to attack due to an authentication glitch, the company reported Tuesday.

The problem applies to Cisco access points operating in Lightweight Access Point Protocol (LWAPP) mode, which are controlled by a separate WLAN switch. According to a security advisory on Ciscos Web site, the access points “may allow unauthenticated end hosts to send unencrypted traffic to a secure network by sending frames from the MAC (Media Access Control) address of an already authenticated end host.”

“Such traffic needs to be sourced from the MAC address of a legitimate, already authenticated end host,” the advisory says. “By exploiting this vulnerability, an attacker may send malicious traffic into a secure network. Legitimate end hosts will still communicate with the access point in an encrypted manner.”

/zimages/1/28571.gifMac OS X Update Swats Five Security Bugs.Click hereto read more.

Specifically the vulnerability applies to Cisco 1200, 1131, and 1240 series access points that are controlled by Cisco 2000 and 4400 series Airespace Wireless LAN (WLAN) Controllers. Access points that run autonomous mode are not affected.

The problem can be solved with a free upgrade to the software on the controller, a spokesman for Cisco said. (In LWAPP mode of operation, it is not possible to change the software on the access points individually. Such access points download their software from the WLAN controller.)

/zimages/1/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.