cbcvebase.
CVE-2021-34740
published 2021-09-23

CVE-2021-34740: A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent…

high7.4CVSS 3.1
AVAACLPRNUINSCCNINAH
A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect error handling when an affected device receives an unexpected 802.11 frame. An attacker could exploit this vulnerability by sending certain 802.11 frames over the wireless network to an interface on an affected AP. A successful exploit could allow the attacker to cause a packet buffer leak. This could eventually result in buffer allocation failures, which would trigger a reload of the affected device.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscoaironet_access_point_software
ciscoaironet_access_point_software
ciscoaironet_access_point_software>= 8.10.0 < 8.10.162.08.10.162.0
ciscoaironet_access_points_wlan_control_protocol_packet
ciscocisco_aironet_access_point_software