CVE-2018-0415 Details
Description
A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Small Business 300 Series Wireless Access Points could allow an authenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper processing of certain EAPOL frames. An attacker could exploit this vulnerability by sending a stream of crafted EAPOL frames to an affected device. A successful exploit could allow the attacker to force the access point (AP) to disassociate all the associated stations (STAs) and to disallow future, new association requests. Cisco Bug IDs: CSCvj97472.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 25, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180815-csb-wap-dos | CVE | Vendor Advisory |
| http://www.securityfocus.com/bid/105116 | CVE | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180815-csb-wap-dos | [email protected] | Vendor Advisory |
| http://www.securityfocus.com/bid/105116 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-388 | 7PK - Errors | [email protected] |
| CWE-388 | 7PK - Errors | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco wap121 firmware | <= 1.0.6.6 |
CPE
Remediation
| |
| cisco wap121 | All versions |
CPE
Remediation
| |
| cisco wap125 firmware | <= 1.0.6.6 |
CPE
Remediation
| |
| cisco wap125 | All versions |
CPE
Remediation
| |
| cisco wap131 firmware | <= 1.0.6.6 |
CPE
Remediation
| |
| cisco wap131 | All versions |
CPE
Remediation
| |
| cisco wap150 firmware | <= 1.0.6.6 |
CPE
Remediation
| |
| cisco wap150 | All versions |
CPE
Remediation
| |
| cisco wap321 firmware | <= 1.0.6.6 |
CPE
Remediation
| |
| cisco wap321 | All versions |
CPE
Remediation
| |
| cisco wap351 firmware | <= 1.0.6.6 |
CPE
Remediation
| |
| cisco wap351 | All versions |
CPE
Remediation
| |
| cisco wap361 firmware | <= 1.0.6.6 |
CPE
Remediation
| |
| cisco wap361 | All versions |
CPE
Remediation
| |
| cisco wap371 firmware | <= 1.0.6.6 |
CPE
Remediation
| |
| cisco wap371 | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Oct 15, 2018 | Initial Analysis | [email protected] |
| Aug 22, 2018 | CVE Modified | [email protected] |