CVE-2018-0441: Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a corruption of certain timer mechanisms triggered by specific roaming events. This corruption will eventually cause a timer crash. An attacker could exploit this vulnerability by sending malicious reassociation events multiple times to the same AP in a short period of time, causing a DoS condition on the affected AP.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-0441?
CVE-2018-0441 is a vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software.
How does CVE-2018-0441 impact Cisco IOS Access Points?
CVE-2018-0441 could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
What is the severity of CVE-2018-0441?
CVE-2018-0441 has a severity rating of 7.4, which is considered high.
How can I mitigate the impact of CVE-2018-0441?
Cisco has released security updates to address CVE-2018-0441. Apply the necessary patches as soon as possible.
Where can I find more information about CVE-2018-0441?
You can find more information about CVE-2018-0441 on the Cisco Security Advisories website.