#VU12387 Improper input validation in Cisco Aironet 1850 Series Access Points - CVE-2018-0234
Published: May 7, 2018
Cisco Aironet 1850 Series Access Points
Cisco Systems, Inc
Description
The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.
The weakness exists in the implementation of Point-to-Point Tunneling Protocol (PPTP) functionality due to insufficient validation of Generic Routing Encapsulation (GRE) frames that pass through the data plane of an affected access point. A remote attacker can initiate a PPTP connection to an affected access point from a device that is registered to the same wireless network as the access point and sending a malicious GRE frame through the data plane of the access point and cause the service to crash.