Cisco’s wireless LANs could be open to a ‘SkyJack’
By Asavin Wattanajantra,
Some Cisco LAN (Local Area Network) devices have a vulnerability that could allow a hacker to hit them with a Denial of Service (DoS) attack.
According to a Cisco alert, the flaw is due to the devices not having enough security for wireless access point association sequences.
An attacker could exploit the vulnerability by injecting malicious packets into the wireless network, where newly added access points are seeking controllers.
With the exploit the attacker could make the LAN device associate with a ‘rogue’ controller, preventing the device from servicing network clients and resulting in a DoS.
Security firm AirMagnet originally found the vulnerability, calling it ‘SkyJacking’. It said that if the Cisco access point connected to the ‘rogue’ controller, it could lead outside an enterprise and therefore be under outside control.
“This same mechanism could be done intentionally by a hacker to purposely SkyJack access points and take control of an enterprise’s access point,” said the company.
However, Cisco replied that there was no risk of data loss or interception at the rogue access point or wireless LAN controller, and that a DoS would be the only problem.
The Cisco Lightweight Wireless Access Point 1100 and 1200 series devices are affected. Cisco said that software updates were not yet available.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Network Access Control Analysis & Insight
Welcome to the stay-at-home Olympics
Inside the Enterprise: The Government has warned of disruption, and the Civil Service is practising working from home. Could IT yet save businesses from chaos on an Olympian scale?
Latest Network Access Control Reviews
ForeScout Technologies CounterACT 6.3.4
Rating: ![]()
advertisement
Most popular
- Apple iPad 3 vs iPad 2 head-to-head review
- Dell EqualLogic PS6100XS review
- Chromebooks: What's gone wrong?
- ICO: Fines for cookie law breakers
- UK regulator shuts down Angry Birds scam
- Open source software driving cloud-based innovation
- Fujitsu targets enterprises with Android ICS tablet
- IBM bans use of Siri on iPhones
- Dell PowerEdge R820 review
- BlackBerry 7 OS certified to carry 'Restricted' UK government information
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






Cisco should not downplay this vulnerability
A dangerous exploit that can be carried out using this vulnerability is for a hacker to route an enterprise customer’s Cisco AP to WLC deployed out in the Internet and change the Guest SSID to map to an internal enterprise VLAN (using REAP mode supported on Cisco APs); more on this - http://blog.airtightnetworks.com
By Sri_Sundaralingam on Wednesday Aug 26