|
|
|
|
| |
Credit:
The original article can be found at: http://www.cisco.com/warp/public/707/cisco-sa-20100811-wcs.shtml
|
| |
Vulnerable Systems:
* Cisco WCS devices running software 6.0.x
Immune Systems:
* Cisco WCS software release 7.0
* Cisco WCS version 7.0.164.0
* Cisco WCS software releases prior to 6.0
* Cisco Wireless LAN Controllers (WLC)
Cisco WCS enables an administrator to configure and monitor one or more WLCs and associated access points. A SQL injection vulnerability exists in Cisco WCS. Exploitation could allow an authenticated attacker to modify system configuration; create, modify and delete users; or modify the configuration of wireless devices managed by WCS.
Workaround:
There are no workarounds for this vulnerability. Mitigation techniques that can be deployed on Cisco devices within the network are available in the Cisco Applied Mitigation Bulletin companion document for this advisory: http://www.cisco.com/warp/public/707/cisco-amb-20100811-wcs.shtml
CVE Information:
CVE-2010-2826
Disclosure Timeline:
2010-August-11: Initial public release.
|
|
|
|
|