Denial of Service Vulnerability in Cisco Small Business Wireless Access Points
CVE-2018-0415

6.8MEDIUM

Summary

A vulnerability exists in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series and 300 Series Wireless Access Points. This flaw enables an authenticated, adjacent attacker to potentially disrupt services by sending a series of specially crafted EAPOL frames to the affected device. Successfully exploiting this vulnerability may lead to a denial of service condition, causing the access point to disassociate all connected stations, thus preventing future association requests from new devices.

Affected Version(s)

Small Business 100 Series Wireless Access Points = unspecified

Small Business 300 Series Wireless Access Points = unspecified

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.