<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Nmap Scan indicates open ports on 5580 WLC from a client connected wirelessly. in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3866754#M204368</link>
    <description>Is your management interface in the same VLAN as your users clients? That could also cause this (it's advised not to do this).&lt;BR /&gt;</description>
    <pubDate>Mon, 03 Jun 2019 12:04:29 GMT</pubDate>
    <dc:creator>patoberli</dc:creator>
    <dc:date>2019-06-03T12:04:29Z</dc:date>
    <item>
      <title>Nmap Scan indicates open ports on 5580 WLC from a client connected wirelessly.</title>
      <link>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3864104#M204365</link>
      <description>&lt;P&gt;Recently we ran a Nmap scan of our wireless network using a client connected via Wifi.&amp;nbsp; The scan showed common ports over the dynamic interfaces (80,443, 22,) as open and reachable from the client.&amp;nbsp; Further testing showed that we were able to connect to the dynamic interface IP over one of the open ports.&amp;nbsp; I suspect this may be a vulnerability that Cisco needs to address. Any suggestions as to what can be done to restrict access to the dynamic interfaces over these ports?&amp;nbsp; We have attempted to apply an ACL&amp;nbsp; to the dynamic and WLAN interfaces without any success.&amp;nbsp; Keep in mind the dynamic interfaces are reachable from a client over the CAPWAP tunnel.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 17:28:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3864104#M204365</guid>
      <dc:creator>mt3368</dc:creator>
      <dc:date>2021-07-05T17:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Nmap Scan indicates open ports on 5580 WLC from a client connected wirelessly.</title>
      <link>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3864273#M204366</link>
      <description>Which firmware are you running?&lt;BR /&gt;There somewhere once was an option to allow "management over wireless", if that is enabled, then those ports are accessible. I currently can't find the option on my WLC though, but am a tad short on time.</description>
      <pubDate>Wed, 29 May 2019 07:02:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3864273#M204366</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-05-29T07:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: Nmap Scan indicates open ports on 5580 WLC from a client connected wirelessly.</title>
      <link>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3864648#M204367</link>
      <description>&lt;P&gt;We are running 8.2.170.&amp;nbsp; &amp;nbsp;The&amp;nbsp;&lt;SPAN&gt;management over wireless option is not enabled.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 18:03:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3864648#M204367</guid>
      <dc:creator>mt3368</dc:creator>
      <dc:date>2019-05-29T18:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: Nmap Scan indicates open ports on 5580 WLC from a client connected wirelessly.</title>
      <link>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3866754#M204368</link>
      <description>Is your management interface in the same VLAN as your users clients? That could also cause this (it's advised not to do this).&lt;BR /&gt;</description>
      <pubDate>Mon, 03 Jun 2019 12:04:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3866754#M204368</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-06-03T12:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Nmap Scan indicates open ports on 5580 WLC from a client connected wirelessly.</title>
      <link>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3866879#M204369</link>
      <description>It is not in the same vlan.&lt;BR /&gt;</description>
      <pubDate>Mon, 03 Jun 2019 15:36:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3866879#M204369</guid>
      <dc:creator>mt3368</dc:creator>
      <dc:date>2019-06-03T15:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Nmap Scan indicates open ports on 5580 WLC from a client connected wirelessly.</title>
      <link>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3868622#M204370</link>
      <description>&lt;P&gt;Some weeks ago a security issue was uncovered in regards to open ports directly on the 2800, 1800, 3800 APs, but I don't think the same applies here.&lt;/P&gt;
&lt;P&gt;I just checked my WLC and scanned its dynamic interface with a wireless client inside that VLAN and nmap showed SSH and HTTPS as open ports. I tried to connect to them, but the WLC (correctly) refused the connection. So I think those ports are indeed open, but no service is offered to the client behind those ports.&lt;/P&gt;
&lt;P&gt;Using 8.5.140.0 here on a 5520.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 06:19:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3868622#M204370</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-06-06T06:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: Nmap Scan indicates open ports on 5580 WLC from a client connected wirelessly.</title>
      <link>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3868878#M204371</link>
      <description>That is the behavior I am seeing as well. Try to telnet to one of the dynamic interfaces over any of those ports then escape (ESC) or control-c and you should see a response from the WLC. While I have not been able to get a login prompt using this method, it still seems to be something that needs to be addressed by Cisco.&lt;BR /&gt;</description>
      <pubDate>Thu, 06 Jun 2019 13:25:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/nmap-scan-indicates-open-ports-on-5580-wlc-from-a-client/m-p/3868878#M204371</guid>
      <dc:creator>mt3368</dc:creator>
      <dc:date>2019-06-06T13:25:06Z</dc:date>
    </item>
  </channel>
</rss>

