First published: Wed Feb 14 2007(Updated: )
The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the WLAN.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Aruba Mobility Controller | =6000 | |
Alcatel-Lucent OmniAccess Wireless | =43xx | |
Alcatel-Lucent OmniAccess Wireless | =6000 | |
Arubanetworks Aruba Mobility Controller | =800 | |
Arubanetworks Aruba Mobility Controller | =200 | |
Arubanetworks Aruba Mobility Controller | =2400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0932 has a medium severity level due to improper implementation of authentication that may allow remote access to administrative interfaces.
CVE-2007-0932 affects several Aruba Mobility Controllers (200, 600, 2400, and 6000) and Alcatel-Lucent OmniAccess Wireless devices (43xx and 6000).
To mitigate CVE-2007-0932, ensure proper authentication and privilege assignments are implemented for guest accounts on affected devices.
Yes, vendors typically release patches or updates to address CVE-2007-0932, so it is advised to check with the respective vendor for security updates.
Exploitation of CVE-2007-0932 can lead to unauthorized access to sensitive administrative interfaces and network resources.