Cisco rags vulnerabilities in tiny business routers and wireless LAN controllers

Cisco Systems expelled new firmware versions for some of a tiny business routers and wireless LAN controllers in sequence to residence vulnerabilities that could concede remote enemy to concede a exposed inclination or impact their availability.

A disadvantage found in a web government interface of a Cisco RV110W Wireless-N VPN Firewall, RV215W Wireless-N VPN Router and CVR100W Wireless-N VPN Router can be exploited by an unauthenticated, remote assailant to benefit executive entrance to a influenced devices.

“The disadvantage is due to crude doing of authentication requests by a web framework,” Cisco pronounced in a security advisory published Wednesday. “An assailant could feat this disadvantage by intercepting, modifying and resubmitting an authentication request. Successful exploitation of this disadvantage could give an assailant administrative-level entrance to a web-based administration interface on a influenced device.”

Cisco reserved an impact measure of 10 to a vulnerability—the top in a Common Vulnerability Scoring System (CVSS)—because a smirch can lead to a finish concede of a device’s confidentiality, firmness and availability.

Users are suggested to refurbish a firmware of a influenced inclination since there are no accessible workarounds. The patched firmware versions are: Cisco CVR100W Wireless-N VPN Router firmware chronicle 1.0.1.21, Cisco RV110W Wireless-N VPN Firewall firmware chronicle 1.2.0.10 and Cisco RV215W Wireless-N VPN Router firmware chronicle 1.1.0.6.

Cisco also bound 5 denial-of-service vulnerabilities and one unapproved entrance disadvantage in a program regulating on a far-reaching operation of a stand-alone and modular wireless LAN controllers. The influenced products are: Cisco 500 Series Wireless Express Mobility Controllers, Cisco 2000 Series Wireless LAN Controllers, Cisco 2100 Series Wireless LAN Controllers, Cisco 2500 Series Wireless Controllers, Cisco 4100 Series Wireless LAN Controllers, Cisco 4400 Series Wireless LAN Controllers, Cisco 5500 Series Wireless Controllers, Cisco Flex 7500 Series Wireless Controllers, Cisco 8500 Series Wireless Controllers, Cisco Virtual Wireless Controller, Cisco Catalyst 6500 Series/7600 Series Wireless Services Module (Cisco WiSM), Cisco Wireless Services Module chronicle 2 (WiSM2), Cisco NME-AIR-WLC Module for Integrated Services Routers (ISRs), Cisco NM-AIR-WLC Module for Integrated Services Routers (ISRs), Cisco Catalyst 3750G Integrated WLC and Cisco Wireless Controller Software for Services-Ready Engine (SRE).

The denial-of-service vulnerabilities can be exploited by promulgation specifically crafted IGMP chronicle 3 messages, MLD chronicle 2 packets, ethernet 802.11 frames and WebAuth login requests to a influenced devices. The attacks can force a influenced inclination to restart or can outcome in some-more determined denial-of-service conditions, depending on a disadvantage being exploited.

The unapproved entrance disadvantage is located in formula that Cisco wireless LAN controllers send to other entrance indicate inclination connected to them.

“An assailant could feat this disadvantage by attempting to substantiate to an influenced device regulating locally-stored certification of a AP,” Cisco pronounced in an advisory. “A successful conflict could concede an assailant to take finish control of a influenced AP and make capricious changes to a configuration.”

The Cisco advisory contains tables inventory a influenced firmware releases for a opposite products as good as a analogous new patched firmware versions.

Article source: http://www.pcworld.com/article/2105360/cisco-patches-vulnerabilities-in-small-business-routers-and-wireless-lan-controllers.html#tk.rss_all