vulnerability

Cisco IOS: cisco-sa-20031202-SNMP-trap: SNMP Trap Reveals WEP Key in Cisco Aironet Access Point

Severity
6
CVSS
(AV:A/AC:L/Au:N/C:C/I:N/A:N)
Published
Sep 26, 2017
Added
Sep 26, 2017
Modified
Feb 19, 2025

Description

Cisco Aironet Access Points (AP) running Cisco IOS software will send any static Wired Equivalent Privacy (WEP) key in the cleartext to the Simple Network Management Protocol (SNMP) server if the snmp-server enable traps wlan-wep command is enabled. Affected hardware models are the Cisco Aironet 1100, 1200, and 1400 series. This command is disabled by default. The workaround is to disable this command. Any dynamically set WEP key will not be disclosed.

Solution

cisco-ios-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.