HTTP GET Vulnerability in AP1x00

Related Vulnerabilities: CVE-2003-0511  

A vulnerability has been reported by an external researcher in Cisco IOS® release for Cisco Aironet AP1x00 Series Wireless devices. The vulnerability affects only IOS-based Cisco Aironet Wireless products. The VxWorks based Cisco Aironet Wireless Devices are not affected. This vulnerability can cause the AP1x00 to reload and is documented as Cisco bug ID CSCeb49869 ( registered customers only) (also CAN-2003-0511). There are workarounds available to mitigate the effects of this vulnerability. This advisory is posted at http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20030728-ap1x00. The external report can be found at http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003001.htm . A second external report found at http://www.vigilante.com/inetsecurity/advisories/VIGILANTE-2003002.htm details another issue, Cisco bug ID CSCdz29724 ( registered customers only) , which is present in all IOS software and is duplicated by the AP1x00 specific Cisco bug ID CSCeb49842 ( registered customers only) (also CAN-2003-512). More details on it can be found at http://www.cisco.com/warp/public/707/cisco-sn-20030724-ios-enum.shtml.