HIGH · 7.1

CVE-2014-7998

Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a malformed EAP packet, aka Bug ID CSCul15509.

Vulnerability Description

Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a malformed EAP packet, aka Bug ID CSCul15509.

CVSS Score

7.1

HIGH

AV:N/AC:M/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoIos-
CiscoAironet 1040-
CiscoAironet 1140-
CiscoAironet 1260-
CiscoAironet 3500-
CiscoAironet 3600-
CiscoAironet 3600E-
CiscoAironet 3600I-
CiscoAironet 3600P-
CiscoAironet 600 Office Extend-
CiscoAironet Ap1100All versions
CiscoAironet Ap1130AgAll versions
CiscoAironet Ap1131All versions
CiscoAironet Ap1200All versions
CiscoAironet Ap1230AgAll versions
CiscoAironet Ap1240All versions
CiscoAironet Ap1240AgAll versions
CiscoAironet Ap1300All versions
CiscoAironet Ap1400All versions
CiscoAironet Ap340All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-7998?

CVE-2014-7998 is a vulnerability with a CVSS score of 7.1 (HIGH). Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a malformed EAP packet, aka Bug ID CSCul15509.

How severe is CVE-2014-7998?

CVE-2014-7998 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-7998?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios, Cisco Aironet 1040, Cisco Aironet 1140, Cisco Aironet 1260, Cisco Aironet 3500.