Ekahau Real-Time Location System Multiple Vulnerabilities (CVE-2014-2716)
Release date:
Updated on:
Affected Systems:
Ekahau Real-Time Location System 6.0.5-FINAL
Description:
Bugtraq id: 71674
CVE (CAN) ID: CVE-2014-2716
Ekahau Real-Time Location System is a wi-fi-based Real-Time Location System solution.
The information encryption mechanism used by Ekahau Real-Time Location System (based on the pre-shared key PSK wireless transmission layer encryption WPA2 solution) has a security vulnerability in implementation, attackers can exploit these vulnerabilities to read and generate arbitrary information, including button events, text/alarm messages, or send reconfiguration events.
<* Source: David Gullasch
Max Moser
Link: http://www.securityfocus.com/archive/1/534241
*>
Suggestion:
Vendor patch:
Ekahau
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.ekahau.com/real-time-location-system/solutions
This article permanently updates the link address: