Vulnerability CVE-2009-2861


Published: 2009-08-27   Modified: 2012-02-13

Description:
The Over-the-Air Provisioning (OTAP) functionality on Cisco Aironet Lightweight Access Point 1100 and 1200 devices does not properly implement access-point association, which allows remote attackers to spoof a controller and cause a denial of service (service outage) via crafted remote radio management (RRM) packets, aka "SkyJack" or Bug ID CSCtb56664.

Type:

CWE-Other

CVSS2 => (AV:A/AC:M/Au:N/C:N/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.3/10
9.2/10
5.5/10
Exploit range
Attack complexity
Authentication
Adjacent network
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Complete
Complete
Affected software
Cisco -> Aironet ap1100 
Cisco -> Aironet ap1200 

 References:
http://tools.cisco.com/security/center/viewAlert.x?alertId=18919
http://www.vupen.com/english/advisories/2009/2419
http://www.securityfocus.com/bid/36145
http://www.airmagnet.com/news/press_releases/2009/08252009.php
http://www.airmagnet.com/assets/AM_Technote_SkyJack_082509.pdf
http://securitytracker.com/id?1022774

Copyright 2021, cxsecurity.com

 

Back to Top