cbcvebase.
CVE-2018-0412
published 2018-08-15

CVE-2018-0412: A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access…

PriorityP424medium5.3CVSS 3.0
AVAACHPRNUINSUCNIHAN
EPSS
0.25%
16.7th percentile
A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Small Business 300 Series Wireless Access Points could allow an unauthenticated, adjacent attacker to force the downgrade of the encryption algorithm that is used between an authenticator (access point) and a supplicant (Wi-Fi client). The vulnerability is due to the improper processing of certain EAPOL messages that are received during the Wi-Fi handshake process. An attacker could exploit this vulnerability by establishing a man-in-the-middle position between a supplicant and an authenticator and manipulating an EAPOL message exchange to force usage of a WPA-TKIP cipher instead of the more secure AES-CCMP cipher. A successful exploit could allow the attacker to conduct subsequent cryptographic attacks, which could lead to the disclosure of confidential information. Cisco Bug IDs: CSCvj29229.

Affected

11 ranges
VendorProductVersion rangeFixed in
ciscosmall_business_100_series_and_300_series_wireless_access_points_encryption_algor
ciscowap121_firmware<= 1.0.6.6
ciscowap125_firmware<= 1.0.6.6
ciscowap131_firmware<= 1.0.6.6
ciscowap150_firmware<= 1.0.6.6
ciscowap321_firmware<= 1.0.6.6
ciscowap351_firmware<= 1.0.6.6
ciscowap361_firmware<= 1.0.6.6
ciscowap371_firmware<= 1.0.6.6
cisco_systems_incsmall_business_100_series_wireless_access_points
cisco_systems_incsmall_business_300_series_wireless_access_points

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.