05-13-2019 11:55 PM - edited 07-05-2021 10:23 AM
Our Vulnerability Scanner says that the cisco AIR-AP2802I-E-K9 is a High Risk.
The Reason for that is that the process Lighttpd is unsecure. Lighttpd is from a another vendor.
When you follow this link you can see that the vendor already fixed this prblem with an update.
https://tools.cisco.com/security/center/viewAlert.x?alertId=60000
But how can I fix this problem? Is Lighttpd integrated in the Cisco IOS and i have to do a cisco update?
The other option is how can I disable lighttpd?
The Vulnerability Scanner hat following Solutionsuggestion: upgrade to version 1.4.54 or later of Lighttpd
how can I update Lighttpd on this accesspoint?
05-14-2019 06:07 AM
NO idea how "accurate" the scan is. The LIGHTTPD vulnerability was discovered way back 2014 and affects only IOS-XR.
1800/2800/3800 don't run this kind of code.
05-16-2019 03:48 PM
The LIGHTTPD vulnerability was discovered way back 2014 and affects only IOS-XR.
Um, the link OP provided clearly says CVE-2019-11072, first published 2019 April 22 22:21 GMT.
05-17-2019 06:57 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide