HIGH · 7.3

CVE-2009-2861

The Over-the-Air Provisioning (OTAP) functionality on Cisco Aironet Lightweight Access Point 1100 and 1200 devices does not properly implement access-point association, which allows remote attackers t...

Vulnerability Description

The Over-the-Air Provisioning (OTAP) functionality on Cisco Aironet Lightweight Access Point 1100 and 1200 devices does not properly implement access-point association, which allows remote attackers to spoof a controller and cause a denial of service (service outage) via crafted remote radio management (RRM) packets, aka "SkyJack" or Bug ID CSCtb56664.

CVSS Score

7.3

HIGH

AV:A/AC:M/Au:N/C:N/I:C/A:C
Confidentiality
NONE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoAironet Ap1100All versions
CiscoAironet Ap1200All versions

References

FAQ

What is CVE-2009-2861?

CVE-2009-2861 is a vulnerability with a CVSS score of 7.3 (HIGH). The Over-the-Air Provisioning (OTAP) functionality on Cisco Aironet Lightweight Access Point 1100 and 1200 devices does not properly implement access-point association, which allows remote attackers t...

How severe is CVE-2009-2861?

CVE-2009-2861 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-2861?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Aironet Ap1100, Cisco Aironet Ap1200.