CVE-2018-0441 (CNNVD-201810-984)
中文标题:
Cisco IOS Access Points Software 安全漏洞
英文标题:
Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
漏洞描述
中文描述:
Cisco IOS Access Points(APs)Software是美国思科(Cisco)公司的一套用于管理控制访问接入点设备的软件。 Cisco IOS APs Software中的802.11r Fast Transition feature set存在安全漏洞。物理位置邻近的攻击者可通过多次发送恶意的重新关联事件利用该漏洞造成拒绝服务。
英文描述:
A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a corruption of certain timer mechanisms triggered by specific roaming events. This corruption will eventually cause a timer crash. An attacker could exploit this vulnerability by sending malicious reassociation events multiple times to the same AP in a short period of time, causing a DoS condition on the affected AP.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Aironet Access Point Software | n/a | - | - |
cpe:2.3:a:cisco:cisco_aironet_access_point_software:n_a:*:*:*:*:*:*:*
|
| cisco | access_points | 8.0\(140.0\) | - | - |
cpe:2.3:o:cisco:access_points:8.0\(140.0\):*:*:*:*:*:*:*
|
| cisco | access_points | 8.2\(141.0\) | - | - |
cpe:2.3:o:cisco:access_points:8.2\(141.0\):*:*:*:*:*:*:*
|
| cisco | access_points | 8.2\(151.0\) | - | - |
cpe:2.3:o:cisco:access_points:8.2\(151.0\):*:*:*:*:*:*:*
|
| cisco | access_points | 8.3\(102.0\) | - | - |
cpe:2.3:o:cisco:access_points:8.3\(102.0\):*:*:*:*:*:*:*
|
| cisco | access_points | 8.3\(112.0\) | - | - |
cpe:2.3:o:cisco:access_points:8.3\(112.0\):*:*:*:*:*:*:*
|
| cisco | access_points | 8.3\(114.74\) | - | - |
cpe:2.3:o:cisco:access_points:8.3\(114.74\):*:*:*:*:*:*:*
|
| cisco | access_points | 15.3\(3\)jd | - | - |
cpe:2.3:o:cisco:access_points:15.3\(3\)jd:*:*:*:*:*:*:*
|
| cisco | access_points | * | - | - |
cpe:2.3:o:cisco:access_points:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.0 (cna)
HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2018-0441 |
2025-11-11 15:19:35 | 2025-11-11 07:34:57 |
| NVD | nvd_CVE-2018-0441 |
2025-11-11 14:55:59 | 2025-11-11 07:43:33 |
| CNNVD | cnnvd_CNNVD-201810-984 |
2025-11-11 15:10:06 | 2025-11-11 07:54:05 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 资源管理错误
- cnnvd_id: 未提取 -> CNNVD-201810-984
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 9
- data_sources: ['cve'] -> ['cve', 'nvd']