CVE-2018-0234 is a denial-of-service vulnerability in Cisco Aironet 1810, 1830, and 1850 Series Access Points running specific Mobility Express Software releases. It stems from insufficient validation of Generic Routing Encapsulation (GRE) frames within the Point-to-Point Tunneling Protocol (PPTP) functionality. An unauthenticated, remote attacker can exploit this by sending a malicious GRE frame, causing the access point to reload. With a CVSS score of 8.6 (High), this vulnerability is easily exploitable over the network with no user interaction, leading to a complete loss of availability. There is currently no public exploit code, evidence of active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.4\(100.0\)CPE matchmatch criteria | cpe:2.3:o:cisco:aironet_access_point_software:8.4\(100.0\):*:*:*:*:*:*:* | ||
8.5\(103.0\)CPE matchmatch criteria | cpe:2.3:o:cisco:aironet_access_point_software:8.5\(103.0\):*:*:*:*:*:*:* | ||
8.5\(105.0\)CPE matchmatch criteria | cpe:2.3:o:cisco:aironet_access_point_software:8.5\(105.0\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.