cbcvebase.
CVE-2018-0441
published 2018-10-17

CVE-2018-0441: A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause…

PriorityP434high7.4CVSS 3.0
AVAACLPRNUINSCCNINAH
EPSS
0.86%
54.3th percentile
A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a corruption of certain timer mechanisms triggered by specific roaming events. This corruption will eventually cause a timer crash. An attacker could exploit this vulnerability by sending malicious reassociation events multiple times to the same AP in a short period of time, causing a DoS condition on the affected AP.

Affected

11 ranges
VendorProductVersion rangeFixed in
ciscoaccess_points< 8.3.140.08.3.140.0
ciscoaccess_points
ciscoaccess_points
ciscoaccess_points
ciscoaccess_points
ciscoaccess_points
ciscoaccess_points
ciscoaccess_points
ciscoaccess_points>= 8.4 < 8.5.110.08.5.110.0
ciscocisco_aironet_access_point_software
ciscoios_access_points

CVSS provenance

nvdv3.07.4HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.