Cisco Wireless Control System SQL Injection Vulnerability
30 Sep. 2010
Summary
Cisco Wireless Control System (WCS) contains a SQL injection vulnerability that could allow an authenticated attacker full access to the vulnerable device, including modification of system configuration; create, modify and delete users; or modify the configuration of wireless devices managed by WCS.
Immune Systems:
* Cisco WCS software release 7.0
* Cisco WCS version 7.0.164.0
* Cisco WCS software releases prior to 6.0
* Cisco Wireless LAN Controllers (WLC)
Cisco WCS enables an administrator to configure and monitor one or more WLCs and associated access points. A SQL injection vulnerability exists in Cisco WCS. Exploitation could allow an authenticated attacker to modify system configuration; create, modify and delete users; or modify the configuration of wireless devices managed by WCS.
Workaround:
There are no workarounds for this vulnerability. Mitigation techniques that can be deployed on Cisco devices within the network are available in the Cisco Applied Mitigation Bulletin companion document for this advisory: http://www.cisco.com/warp/public/707/cisco-amb-20100811-wcs.shtml