Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2023-06267

Опубликовано: 27 сент. 2023
Источник: fstec
CVSS3: 4.7
CVSS2: 3.3
EPSS Низкий

Описание

Уязвимость функции обработки пакетов микропрограммного обеспечения точек доступа Cisco Aironet Access Points (AP) связана с неконтролируемым расходом ресурсов. Эксплуатация уязвимости может позволить нарушителю вызвать отказ в обслуживании

Вендор

Cisco Systems Inc.

Наименование ПО

Integrated AP on 1100 Integrated Services Routers
Cisco Embedded Services 6300 Series APs
Catalyst 9100 APs
Catalyst IW6300 Heavy Duty Series APs
Aironet 1540 Series APs
Aironet 1560 Series APs
Aironet 1800 Series APs
Aironet 2800 Series APs
Aironet 3800 Series APs
Aironet 4800 APs
Cisco Business 150 AP
Cisco Business 151 Mesh Extender

Версия ПО

- (Integrated AP on 1100 Integrated Services Routers)
до 17.3.8 (Cisco Embedded Services 6300 Series APs)
от 17.4 до 17.6.6 (Cisco Embedded Services 6300 Series APs)
от 17.8 до 17.9.4 (Cisco Embedded Services 6300 Series APs)
от 17.10 до 17.12 (Cisco Embedded Services 6300 Series APs)
до 17.3.8 (Catalyst 9100 APs)
от 17.4 до 17.6.6 (Catalyst 9100 APs)
от 17.8 до 17.9.4 (Catalyst 9100 APs)
от 17.10 до 17.12 (Catalyst 9100 APs)
до 17.3.8 (Catalyst IW6300 Heavy Duty Series APs)
от 17.4 до 17.6.6 (Catalyst IW6300 Heavy Duty Series APs)
от 17.8 до 17.9.4 (Catalyst IW6300 Heavy Duty Series APs)
от 17.10 до 17.12 (Catalyst IW6300 Heavy Duty Series APs)
до 8.10.190.0 (Aironet 1540 Series APs)
до 8.10.190.0 (Aironet 1560 Series APs)
до 8.10.190.0 (Aironet 1800 Series APs)
до 8.10.190.0 (Aironet 2800 Series APs)
до 8.10.190.0 (Aironet 3800 Series APs)
до 8.10.190.0 (Aironet 4800 APs)
до 10.6.2.0 (Cisco Business 150 AP)
до 10.6.2.0 (Cisco Business 151 Mesh Extender)

Тип ПО

ПО сетевого программно-аппаратного средства
Сетевое программное средство
Прикладное ПО информационных систем
Микропрограммный код

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Низкий уровень опасности (базовая оценка CVSS 2.0 составляет 3,3)
Средний уровень опасности (базовая оценка CVSS 3.0 составляет 4,7)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ap-dos-capwap-DDMCZS4m

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 11%
0.00039
Низкий

4.7 Medium

CVSS3

3.3 Low

CVSS2

Связанные уязвимости

CVSS3: 4.7
nvd
больше 2 лет назад

A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device.  This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A sustained attack could lead to the disruption of the Control and Provisioning of Wireless Access Points (CAPWAP) tunnel and intermittent loss of wireless client traffic.

CVSS3: 4.7
github
больше 2 лет назад

A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device. This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A sustained attack could lead to the disruption of the Control and Provisioning of Wireless Access Points (CAPWAP) tunnel and intermittent loss of wireless client traffic.

EPSS

Процентиль: 11%
0.00039
Низкий

4.7 Medium

CVSS3

3.3 Low

CVSS2