CVE-2016-9221
published 2017-01-26CVE-2016-9221: A Denial of Service Vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could…
PriorityP420medium4.3CVSS 3.0
AVAACLPRNUINSUCNINAL
EPSS
0.54%
42.0th percentile
A Denial of Service Vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause authentication to fail. Affected Products: This vulnerability affects Cisco Mobility Express 2800 Series and 3800 Series Access Points when configured in local mode in 40 MHz. More Information: CSCvb33575. Known Affected Releases: 8.2(121.12) 8.4(1.82). Known Fixed Releases: 8.2(131.2) 8.2(131.3) 8.2(131.4) 8.2(141.0) 8.3(104.53) 8.3(104.54) 8.4(1.80) 8.4(1.85).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | aironet_access_point_software | — | — |
| cisco | aironet_access_point_software | — | — |
| cisco | mobility_express_2800_and_3800 | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Mobility Express 2800 and 3800 Denial of Service Vulnerability
vendor_cisco·2017-01-18·CVSS 4.3
CVE-2016-9221 [MEDIUM] CWE-399 Cisco Mobility Express 2800 and 3800 Denial of Service Vulnerability
Cisco Mobility Express 2800 and 3800 Denial of Service Vulnerability
A vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause authentication to fail.
The vulnerability is due to improper error handling for 802.11 authentication requests that do not complete. An attacker could exploit this vulnerability by sending a crafted 802.11 frame to the targeted device. An exploit could allow the attacker to impact the availability of the device due to authentication failures.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cis
Cisco
Cisco Mobility Express 2800 and 3800 Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2016-9221 Cisco Mobility Express 2800 and 3800 Denial of Service Vulnerability
CVE-2016-9221: Cisco Mobility Express 2800 and 3800 Denial of Service Vulnerability
A vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause authentication to fail. The vulnerability is due to improper error handling for 802.11 authentication requests that do not complete. An attacker could exploit this vulnerability by sending a crafted 802.11 frame to the targeted device. An exploit could allow the attacker to impact the availability of the device due to authentication failures. There are no
CVSS: 3.0
CWE: CWE-399, CWE-399
Bug IDs: CSCvb33575
GHSA
GHSA-h84g-xq42-7q7f: A Denial of Service Vulnerability in 802
ghsa_unreviewed·2022-05-17
CVE-2016-9221 [MEDIUM] GHSA-h84g-xq42-7q7f: A Denial of Service Vulnerability in 802
A Denial of Service Vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause authentication to fail. Affected Products: This vulnerability affects Cisco Mobility Express 2800 Series and 3800 Series Access Points when configured in local mode in 40 MHz. More Information: CSCvb33575. Known Affected Releases: 8.2(121.12) 8.4(1.82). Known Fixed Releases: 8.2(131.2) 8.2(131.3) 8.2(131.4) 8.2(141.0) 8.3(104.53) 8.3(104.54) 8.4(1.80) 8.4(1.85).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-01-26
Published