// For flags

CVE-2018-0234

 

Severity Score

8.6
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the implementation of Point-to-Point Tunneling Protocol (PPTP) functionality in Cisco Aironet 1810, 1830, and 1850 Series Access Points could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Generic Routing Encapsulation (GRE) frames that pass through the data plane of an affected access point. An attacker could exploit this vulnerability by initiating a PPTP connection to an affected access point from a device that is registered to the same wireless network as the access point and sending a malicious GRE frame through the data plane of the access point. A successful exploit could allow the attacker to cause the NSS core process on the affected access point to crash, which would cause the access point to reload and result in a DoS condition. This vulnerability affects Cisco Aironet 1810, 1830, and 1850 Series Access Points that are running Cisco Mobility Express Software Release 8.4.100.0, 8.5.103.0, or 8.5.105.0 and are configured as a master, subordinate, or standalone access point. Cisco Bug IDs: CSCvf73890.

Una vulnerabilidad en la implementación de la funcionalidad PPTP (Point-to-Point Tunneling Protocol) en los puntos de acceso de las series 1810, 1830 y 1850 de Cisco Aironet podría permitir que un atacante remoto no autenticado provocara el reinicio de un dispositivo afectado, lo que provocaría una condición de denegación de servicio (DoS). La vulnerabilidad se debe a la validación insuficiente de las tramas GRE (Generic Routing Encapsulation) que pasan a través del plano de datos de un punto de acceso afectado. Un atacante podría explotar esta vulnerabilidad iniciando una conexión PPTP a un punto de acceso afectado desde un dispositivo registrado en la misma red inalámbrica que el punto de acceso y enviando un marco GRE malicioso a través del plano de datos del punto de acceso. Su explotación con éxito podría permitir al atacante causar que el proceso del núcleo NSS en el punto de acceso afectado se bloquee, lo que causaría que el punto de acceso se reinicie y una condición de denegación de servicio. Esta vulnerabilidad afecta a los puntos de acceso de las series 1810, 1830 y 1850 de Cisco Aironet que ejecuten las versiones de software 8.4.100.0, 8.5.103.0 o 8.5.105.0 de Cisco Mobility Express y que estén configurados como puntos de acceso maestro, subordinado o independiente. Cisco Bug IDs: CSCvf73890.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-11-27 CVE Reserved
  • 2018-05-02 CVE Published
  • 2024-02-15 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Aironet Access Point Software
Search vendor "Cisco" for product "Aironet Access Point Software"
8.4\(100.0\)
Search vendor "Cisco" for product "Aironet Access Point Software" and version "8.4\(100.0\)"
-
Affected
Cisco
Search vendor "Cisco"
Aironet Access Point Software
Search vendor "Cisco" for product "Aironet Access Point Software"
8.5\(103.0\)
Search vendor "Cisco" for product "Aironet Access Point Software" and version "8.5\(103.0\)"
-
Affected
Cisco
Search vendor "Cisco"
Aironet Access Point Software
Search vendor "Cisco" for product "Aironet Access Point Software"
8.5\(105.0\)
Search vendor "Cisco" for product "Aironet Access Point Software" and version "8.5\(105.0\)"
-
Affected