CVE-2018-0441
published 2018-10-17CVE-2018-0441: A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause…
PriorityP434high7.4CVSS 3.0
AVAACLPRNUINSCCNINAH
EPSS
0.86%
54.3th percentile
A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a corruption of certain timer mechanisms triggered by specific roaming events. This corruption will eventually cause a timer crash. An attacker could exploit this vulnerability by sending malicious reassociation events multiple times to the same AP in a short period of time, causing a DoS condition on the affected AP.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | access_points | < 8.3.140.0 | 8.3.140.0 |
| cisco | access_points | — | — |
| cisco | access_points | — | — |
| cisco | access_points | — | — |
| cisco | access_points | — | — |
| cisco | access_points | — | — |
| cisco | access_points | — | — |
| cisco | access_points | — | — |
| cisco | access_points | >= 8.4 < 8.5.110.0 | 8.5.110.0 |
| cisco | cisco_aironet_access_point_software | — | — |
| cisco | ios_access_points | — | — |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rv57-79g9-2rpq: A vulnerability in the 802
ghsa_unreviewed·2022-05-13
CVE-2018-0441 [HIGH] CWE-400 GHSA-rv57-79g9-2rpq: A vulnerability in the 802
A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a corruption of certain timer mechanisms triggered by specific roaming events. This corruption will eventually cause a timer crash. An attacker could exploit this vulnerability by sending malicious reassociation events multiple times to the same AP in a short period of time, causing a DoS condition on the affected AP.
Cisco
Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
vendor_cisco·2018-10-17·CVSS 7.4
CVE-2018-0441 [HIGH] CWE-400 Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to a corruption of certain timer mechanisms triggered by specific roaming events. This corruption will eventually cause a timer crash. An attacker could exploit this vulnerability by sending malicious reassociation events multiple times to the same AP in a short period of time, causing a DoS condition on the affected AP.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is
Cisco
Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0441 Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
CVE-2018-0441: Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a corruption of certain timer mechanisms triggered by specific roaming events. This corruption will eventually cause a timer crash. An attacker could exploit this vulnerability by sending malicious reassociation events multiple times to the same AP in a short period of time, causing a DoS condition on the affected AP. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-400, CWE-400
Bug IDs: CSCve6
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/105680http://www.securitytracker.com/id/1041918https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181017-ap-ft-doshttp://www.securityfocus.com/bid/105680http://www.securitytracker.com/id/1041918https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181017-ap-ft-dos
2018-10-17
Published