Junglewise Threat Intelligence

CVE-2016-9221: Cisco Mobility Express DoS in 802.11 authentication handling

CVE-2016-9221 · Severity: medium · CVSS 4.3 · Published 2017-01-26

Vendors: Cisco.

Executive brief

A security flaw in certain Cisco wireless access points can allow a nearby attacker to disrupt Wi-Fi connectivity. By sending specially crafted wireless signals, an attacker can cause the device's authentication process to fail, preventing legitimate users from connecting to the network. This impacts the availability of wireless services but does not allow the attacker to access private data.

Technical details

A Denial of Service (DoS) vulnerability exists in the 802.11 ingress connection authentication handling of Cisco Mobility Express 2800 and 3800 Series Access Points. The root cause is improper error handling for 802.11 authentication requests that do not complete. An unauthenticated, adjacent attacker can exploit this by sending crafted 802.11 frames to a target device configured in local mode at 40 MHz. Successful exploitation prevents new wireless authentications, effectively denying service to legitimate users. Fixed software releases include versions 8.2(131.2), 8.3(104.53), 8.4(1.80), and subsequent updates.

Affected products

  • Cisco Mobility Express 2800 Series Access Points 8.2(121.12), 8.4(1.82)
  • Cisco Mobility Express 3800 Series Access Points 8.2(121.12), 8.4(1.82)

Timeline

  • 2017-01-18: advisory: Initial Cisco advisory published
  • 2017-01-26: disclosed: NVD publication date

References

Related threats