CVE-2017-12283 is a Denial of Service vulnerability affecting Cisco Aironet 3800 Series Access Points running in FlexConnect mode. It stems from improper validation of 802.11w Protected Management Frame (PAF) disassociation and deauthentication frames. An unauthenticated, adjacent attacker can exploit this by sending a spoofed PAF frame, terminating a single valid user connection. The vulnerability has a CVSS score of 6.1 (Medium), indicating a low attack complexity and requiring adjacent network access. The impact is limited to denial of service for individual users, with no confidentiality or integrity compromise. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. It is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:aironet_3800_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.