Member Avatar for Member #2466

Interesting article:
http://www.cisco.com/warp/public/707/cisco-sa-20040407-username.shtml

Any of you system admins out there with Cisco hardware should give this a serious read.

Dani AI

Generated

As noted, Cisco PSIRT published an advisory on April 7, 2004 that a hard‑coded username/password exists in all releases of the Wireless LAN Solution Engine (WLSE) and Hosting Solution Engine (HSE). The account cannot be disabled and, in affected builds, grants full administrative control. Patches were made available for the listed WLSE/HSE releases. (sec.cloudapps.cisco.com)

That kind of factory backdoor is exactly the scenario and were worried about: one undisclosed account with admin rights can be used to hide rogue access points, alter RF plans, or change hosted-site routing — effectively turning the appliance into a foothold for further attacks. The advisory spells out those impacts and stresses there was no workaround in the affected releases. (sec.cloudapps.cisco.com)

Immediate practical steps (applies to any admin who still runs WLSE/HSE or similar appliances):

  • Inventory any WLSE/HSE hardware and note software build/version.
  • If a vulnerable release is present, isolate the device from production networks until patched.
  • Apply the vendor-provided fix or configuration change from Cisco as soon as possible.
  • Harden management access (restrict management interfaces, use ACLs/MPP, enforce SSH/HTTPS only) and move to centralized AAA (TACACS+/RADIUS) so shared or hidden accounts cannot be a single point of failure.
  • Review authentication and system logs for unusual admin activity and rotate credentials where appropriate. (cisco.com)

This incident (April 7, 2004) is a useful reminder: treat vendor defaults as untrusted, require proof of secure development practices from suppliers, and make management‑plane hardening and account auditing part of any deployment checklist. If a patched image is not available or you cannot patch quickly, consider decommissioning or replacing the appliance with a supported, auditable solution. (sec.cloudapps.cisco.com)

Recommended Answers

All 3 Replies

Wow.

How dumb is this? You'd think that in this day and age with all of these security fears we've got going around, Cisco of all places, which offers a FREAKING INTERNET SECURITY CERTIFICATION would have thought better than to hard-code a username/password pair into their firmware.

Ah well... at least they released a patch... :rolleyes:

APC has done the same thing too. It is really disturbing that these big companies would include such backdoors. All it takes is one disgruntled employee to cause a lot of havoc. Sure, the developers of the systems would know of bugs, and other exploits as they did create the product, but setting up a straight-forward backdoor is a bit much.

Member Avatar for Member #2466

Agreed. One disgruntled employee (bad apple) can spoil the lot. Why would they include it in their hardware? Sounds like leaving the key underneath the doormat if you know what I mean...and then putting up a sign with an arrow that points under the mat and says "key" (pink neon, blink blink, blinkety blink)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.