First published: Thu Aug 27 2009(Updated: )
The Over-the-Air Provisioning (OTAP) functionality on Cisco Aironet Lightweight Access Point 1100 and 1200 devices does not properly implement access-point association, which allows remote attackers to spoof a controller and cause a denial of service (service outage) via crafted remote radio management (RRM) packets, aka "SkyJack" or Bug ID CSCtb56664.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Aironet AP1100 | ||
Cisco Aironet AP1200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2861 has been assigned a high severity rating due to its potential to cause denial of service.
To mitigate CVE-2009-2861, it is recommended to upgrade affected Cisco Aironet Lightweight Access Point firmware.
CVE-2009-2861 affects Cisco Aironet Lightweight Access Point 1100 and 1200 models.
CVE-2009-2861 allows remote attackers to spoof a controller, leading to service outages.
As of the latest reports, CVE-2009-2861 has the potential for exploitation, but specific active exploits may vary.