Lucene search

K
cveCiscoCVE-2018-0415
HistoryAug 15, 2018 - 8:29 p.m.

CVE-2018-0415

2018-08-1520:29:00
CWE-388
cisco
web.nvd.nist.gov
39
cve-2018-0415
vulnerability
eapol
authentication
cisco
wireless access points
dos
nvd
cscvj97472

CVSS2

5.5

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:A/AC:L/Au:S/C:N/I:N/A:C

CVSS3

6.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

AI Score

6.5

Confidence

High

EPSS

0

Percentile

12.6%

A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Small Business 300 Series Wireless Access Points could allow an authenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper processing of certain EAPOL frames. An attacker could exploit this vulnerability by sending a stream of crafted EAPOL frames to an affected device. A successful exploit could allow the attacker to force the access point (AP) to disassociate all the associated stations (STAs) and to disallow future, new association requests. Cisco Bug IDs: CSCvj97472.

Affected configurations

Nvd
Node
ciscowap121_firmwareRange1.0.6.6
AND
ciscowap121Match-
Node
ciscowap125_firmwareRange1.0.6.6
AND
ciscowap125Match-
Node
ciscowap131_firmwareRange1.0.6.6
AND
ciscowap131Match-
Node
ciscowap150_firmwareRange1.0.6.6
AND
ciscowap150Match-
Node
ciscowap321_firmwareRange1.0.6.6
AND
ciscowap321Match-
Node
ciscowap351_firmwareRange1.0.6.6
AND
ciscowap351Match-
Node
ciscowap361_firmwareRange1.0.6.6
AND
ciscowap361Match-
Node
ciscowap371_firmwareRange1.0.6.6
AND
ciscowap371Match-
VendorProductVersionCPE
ciscowap121_firmware*cpe:2.3:o:cisco:wap121_firmware:*:*:*:*:*:*:*:*
ciscowap121-cpe:2.3:h:cisco:wap121:-:*:*:*:*:*:*:*
ciscowap125_firmware*cpe:2.3:o:cisco:wap125_firmware:*:*:*:*:*:*:*:*
ciscowap125-cpe:2.3:h:cisco:wap125:-:*:*:*:*:*:*:*
ciscowap131_firmware*cpe:2.3:o:cisco:wap131_firmware:*:*:*:*:*:*:*:*
ciscowap131-cpe:2.3:h:cisco:wap131:-:*:*:*:*:*:*:*
ciscowap150_firmware*cpe:2.3:o:cisco:wap150_firmware:*:*:*:*:*:*:*:*
ciscowap150-cpe:2.3:h:cisco:wap150:-:*:*:*:*:*:*:*
ciscowap321_firmware*cpe:2.3:o:cisco:wap321_firmware:*:*:*:*:*:*:*:*
ciscowap321-cpe:2.3:h:cisco:wap321:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CNA Affected

[
  {
    "product": "Small Business 100 Series Wireless Access Points",
    "vendor": "Cisco Systems, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "unspecified"
      }
    ]
  },
  {
    "product": "Small Business 300 Series Wireless Access Points",
    "vendor": "Cisco Systems, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "unspecified"
      }
    ]
  }
]

CVSS2

5.5

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:A/AC:L/Au:S/C:N/I:N/A:C

CVSS3

6.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

AI Score

6.5

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2018-0415