CVE-2017-3834: Critical severity Cisco Aironet Access Point Firmware vulnerability
A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express Software could allow an unauthenticated, remote attacker to take complete control of an affected device. The vulnerability is due to the existence of default credentials for an affected device that is running Cisco Mobility Express Software, regardless of whether the device is configured as a master, subordinate, or standalone access point. An attacker who has layer 3 connectivity to an affected device could use Secure Shell (SSH) to log in to the device with elevated privileges. A successful exploit could allow the attacker to take complete control of the device. This vulnerability affects Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points that are running an 8.2.x release of Cisco Mobility Express Software prior to Release 8.2.111.0, regardless of whether the device is configured as a master, subordinate, or standalone access point. Release 8.2 was the first release of Cisco Mobility Express Software for next generation Cisco Aironet Access Points. Cisco Bug IDs: CSCva50691.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Mobility Express Software (Cisco Aironet 1830/1850)to a version that resolves this vulnerability.Fixed in 8.2.111.0Patch CSCva50691 - Compensating control
Ensure that default credentials are changed/removed for Cisco Aironet 1830/1850 Access Points running Cisco Mobility Express Software (applies regardless of master, subordinate, or standalone configuration).
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3834?
CVE-2017-3834 is considered a critical vulnerability.
How do I fix CVE-2017-3834?
To fix CVE-2017-3834, change the default credentials and update to the latest firmware version recommended by Cisco.
Which devices are affected by CVE-2017-3834?
CVE-2017-3834 affects Cisco Aironet 1830 Series and 1850 Series Access Points running certain versions of Cisco Mobility Express Software.
Can CVE-2017-3834 be exploited remotely?
Yes, CVE-2017-3834 can be exploited by unauthenticated remote attackers.
What causes the vulnerability in CVE-2017-3834?
The vulnerability in CVE-2017-3834 is due to the presence of default credentials for device access.