HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2021-34740

CVSS 7.4v3.1pub. 2021-09-23upd. 2024-11-21

A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect error handling when an affected device receives an unexpected 802.11 frame. An attacker could exploit this vulnerability by sending certain 802.11 frames over the wireless network to an interface on an affected AP. A successful exploit could allow the attacker to cause a packet buffer leak. This could eventually result in buffer allocation failures, which would trigger a reload of the affected device.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • Cisco 1100 4g\/6g Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 4p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 8p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1101 4p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1101 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1109 2p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1109 4p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1109 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1111x 8p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1111x Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 111x Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1120 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1160 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 6300 Series Access Points

    HW
    Cisco
    all versions
  • Cisco Aironet 1540

    HW
    Cisco
    all versions
  • Cisco Aironet 1542d

    HW
    Cisco
    all versions
  • Cisco Aironet 1542i

    HW
    Cisco
    all versions
  • Cisco Aironet 1560

    HW
    Cisco
    all versions
  • Cisco Aironet 1562d

    HW
    Cisco
    all versions
  • Cisco Aironet 1562e

    HW
    Cisco
    all versions
  • Cisco Aironet 1562i

    HW
    Cisco
    all versions
  • Cisco Aironet 1800

    HW
    Cisco
    all versions
  • Cisco Aironet 1800i

    HW
    Cisco
    all versions
  • Cisco Aironet 1810

    HW
    Cisco
    all versions
  • Cisco Aironet 1810w

    HW
    Cisco
    all versions
  • Cisco Aironet 1815

    HW
    Cisco
    all versions
  • Cisco Aironet 1815i

    HW
    Cisco
    all versions
  • Cisco Aironet 1830

    HW
    Cisco
    all versions
  • Cisco Aironet 1830e

    HW
    Cisco
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2017-12240CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w DHCP relay Cisco IOS — RCE bez uwierzytelnienia

CVE-2022-20695CRITICAL10.0PL ✓same product

Cisco WLC — pominięcie uwierzytelnienia przez management interface

CVE-2021-34727CRITICAL9.8PL ✓same product

Buffer overflow w procesie vDaemon Cisco IOS XE SD-WAN — RCE z uprawnieniami root

CVE-2019-15260CRITICAL9.8PL ✓same product

Cisco Aironet AP — nieautoryzowany dostęp z podwyższonymi uprawnieniami

CVE-2017-3831CRITICAL9.8PL ✓same product

Cisco Mobility Express 1800 — pominięcie uwierzytelnienia w interfejsie web