#VU14435 Improper input validation in Cisco Small Business 300 Series Wireless Access Points and Cisco Small Business 100 Series Wireless Access Points - CVE-2018-0415
Published: August 15, 2018 / Updated: August 16, 2018
Cisco Small Business 300 Series Wireless Access Points
Cisco Small Business 100 Series Wireless Access Points
Cisco Systems, Inc
Description
The vulnerability allows an adjacent authenticated attacker to cause DoS condition on the target system.
The vulnerability exists in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality due to improper processing of certain EAPOL frames. An adjacent attacker can send a stream of specially crafted EAPOL frames, force the access point (AP) to disassociate all the associated stations (STAs) and to disallow future, new association requests.