
====================================================================

                                  CERT-Renater

                      Note d'Information No. 2016/VULN017
_____________________________________________________________________

DATE                : 13/01/2016

HARDWARE PLATFORM(S): Cisco Aironet 1800 Series Access Point.

OPERATING SYSTEM(S): Cisco Aironet 1800 Series Access Point software.

======================================================================
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160113-air
_____________________________________________________________________

Cisco Aironet 1800 Series Access Point Default Static Account 
Credentials Vulnerability

Advisory ID: cisco-sa-20160113-air

Revision 1.0

For Public Release 2016 January 13 16:00 UTC (GMT)

+---------------------------------------------------------------------

Summary
=======

A vulnerability in Cisco Aironet 1800 Series Access Point devices could
allow an unauthenticated, remote attacker to log in to the device by
using a default account that has a static password. By default, the
account does not have full administrative privileges.

The vulnerability is due to the presence of a default user account that
is created when the device is installed. An attacker could exploit this
vulnerability by logging in to the device by using the default account,
which could allow the attacker to gain unauthorized access to the device.

Cisco released software updates that address this vulnerability. There
are no workarounds that mitigate this vulnerability.

This advisory is available at the following link:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160113-air

==========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================




