PT-2021-20654 · Cisco · Cisco Aironet Access Point
Published
2021-09-23
·
Updated
2023-05-22
·
CVE-2021-34740
CVSS v3.1
7.4
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Cisco Aironet Access Point (AP) software (affected versions not specified)
Description:
A vulnerability in the WLAN Control Protocol (WCP) implementation could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. This issue is due to incorrect error handling when an affected device receives an unexpected 802.11 frame. An attacker could exploit this by sending certain 802.11 frames over the wireless network to an interface on an affected AP, potentially causing a packet buffer leak. This could eventually result in buffer allocation failures, triggering a reload of the affected device.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Aironet Access Point