CVE-2016-9221
MEDIUMCisco Mobility Express 2800/3800 Series DoS via 802.11 Auth
Title source: llmDescription
A Denial of Service Vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause authentication to fail. Affected Products: This vulnerability affects Cisco Mobility Express 2800 Series and 3800 Series Access Points when configured in local mode in 40 MHz. More Information: CSCvb33575. Known Affected Releases: 8.2(121.12) 8.4(1.82). Known Fixed Releases: 8.2(131.2) 8.2(131.3) 8.2(131.4) 8.2(141.0) 8.3(104.53) 8.3(104.54) 8.4(1.80) 8.4(1.85).
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170118-cme2
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/95631
Scores
CVSS v3
4.3
EPSS
0.0054
EPSS Percentile
42.3%
Attack Vector
ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Details
CWE
CWE-399
Status
published
Products (3)
cisco/aironet_access_point_software
8.2\(121.12\)
cisco/aironet_access_point_software
8.4\(1.82\)
n/a/Cisco Mobility Express 2800 Series and 3800 Series Access Points
Cisco Mobility Express 2800 Series and 3800 Series Access Points
Published
Jan 26, 2017
Tracked Since
Feb 18, 2026