Junglewise Threat Intelligence

CVE-2016-9220: Cisco Mobility Express DoS in 802.11 ingress packet processing

CVE-2016-9220 · Severity: medium · CVSS 4.3 · Published 2017-01-26

Vendors: Cisco.

Executive brief

A vulnerability in certain Cisco wireless access points could allow an attacker in physical proximity to disrupt Wi-Fi services. By sending specially crafted wireless signals, an attacker can fill the device's connection memory with fake entries, preventing legitimate users from connecting to the network. This results in a denial-of-service condition that impacts local business operations and wireless connectivity.

Technical details

The vulnerability exists in the 802.11 ingress packet processing component of Cisco Mobility Express software. The root cause is a lack of proper error handling when an 802.11 frame is received with an unexpected status code. An unauthenticated attacker within wireless range (adjacent) can exploit this by sending crafted 802.11 frames to the target AP. Successful exploitation causes the device's connection table to fill with invalid entries, preventing the processing of new legitimate requests and resulting in a Denial of Service (DoS). Fixed releases include 8.2(131.6), 8.2(131.10), 8.2(141.0), 8.3(104.56), 8.4(1.88), and 8.4(1.91).

Affected products

  • Cisco Mobility Express 2800 Series Access Points 8.2(130.0)
  • Cisco Mobility Express 3800 Series Access Points 8.2(130.0)

Timeline

  • 2017-01-18: advisory: Initial Cisco advisory release
  • 2017-01-26: disclosed: NVD publication date

References

Related threats