PT-2021-20654 · Cisco · Cisco Aironet Access Point

Published

2021-09-23

·

Updated

2023-05-22

·

CVE-2021-34740

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Cisco Aironet Access Point (AP) software (affected versions not specified)
Description: A vulnerability in the WLAN Control Protocol (WCP) implementation could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. This issue is due to incorrect error handling when an affected device receives an unexpected 802.11 frame. An attacker could exploit this by sending certain 802.11 frames over the wireless network to an interface on an affected AP, potentially causing a packet buffer leak. This could eventually result in buffer allocation failures, triggering a reload of the affected device.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Leak

Weakness Enumeration

Related Identifiers

CVE-2021-34740

Affected Products

Cisco Aironet Access Point