CVE-2016-9221

MEDIUM

Cisco Mobility Express 2800/3800 Series DoS via 802.11 Auth

Title source: llm
STIX 2.1

Description

A Denial of Service Vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause authentication to fail. Affected Products: This vulnerability affects Cisco Mobility Express 2800 Series and 3800 Series Access Points when configured in local mode in 40 MHz. More Information: CSCvb33575. Known Affected Releases: 8.2(121.12) 8.4(1.82). Known Fixed Releases: 8.2(131.2) 8.2(131.3) 8.2(131.4) 8.2(141.0) 8.3(104.53) 8.3(104.54) 8.4(1.80) 8.4(1.85).

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95631

Scores

CVSS v3 4.3
EPSS 0.0054
EPSS Percentile 42.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-399
Status published
Products (3)
cisco/aironet_access_point_software 8.2\(121.12\)
cisco/aironet_access_point_software 8.4\(1.82\)
n/a/Cisco Mobility Express 2800 Series and 3800 Series Access Points Cisco Mobility Express 2800 Series and 3800 Series Access Points
Published Jan 26, 2017
Tracked Since Feb 18, 2026