
====================================================================

                              CERT-Renater

                 Note d'Information No. 2017/VULN067
_____________________________________________________________________

DATE                : 15/03/2017

HARDWARE PLATFORM(S): Cisco Mobility Express 1800 Access Point Series.

OPERATING SYSTEM(S): Cisco Mobility Express 1800 software.

=====================================================================
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-ap1800
____________________________________________________________________

Cisco Security Advisory: Cisco Mobility Express 1800 Access Point
Series Authentication Bypass Vulnerability

Advisory ID: cisco-sa-20170315-ap1800

Revision: 1.0

For Public Release: 2017 March 15 16:00 GMT

Last Updated: 2017 March 15 16:00 GMT

CVE ID(s): CVE-2017-3831

CVSS Score v(3): 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

+---------------------------------------------------------------------

Summary
=======
A vulnerability in the web-based GUI of Cisco Mobility Express 1800
Series Access Points could allow an unauthenticated, remote attacker to
bypass authentication. The attacker could be granted full administrator
privileges.

The vulnerability is due to improper implementation of authentication
for accessing certain web pages using the GUI interface. An attacker
could exploit this vulnerability by sending a crafted HTTP request to
the web interface of the affected system. A successful exploit could
allow the attacker to bypass authentication and perform unauthorized
configuration changes or issue control commands to the affected device.

Cisco has released software updates that address this vulnerability.
There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-ap1800
["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-ap1800"]

==========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================


