Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Wap361_firmware
(Cisco)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 14 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-05-22 | CVE-2021-1555 | Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are due to improper validation of user-supplied input. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit... | Wap125_firmware, Wap131_firmware, Wap150_firmware, Wap351_firmware, Wap361_firmware, Wap581_firmware | 7.2 | ||
2018-08-15 | CVE-2018-0415 | A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Small Business 300 Series Wireless Access Points could allow an authenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper processing of certain EAPOL frames. An attacker could exploit this vulnerability by sending a stream of crafted... | Wap121_firmware, Wap125_firmware, Wap131_firmware, Wap150_firmware, Wap321_firmware, Wap351_firmware, Wap361_firmware, Wap371_firmware | 6.8 | ||
2018-08-15 | CVE-2018-0412 | A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Small Business 300 Series Wireless Access Points could allow an unauthenticated, adjacent attacker to force the downgrade of the encryption algorithm that is used between an authenticator (access point) and a supplicant (Wi-Fi client). The vulnerability is due to the improper processing of certain EAPOL messages that... | Wap121_firmware, Wap125_firmware, Wap131_firmware, Wap150_firmware, Wap321_firmware, Wap351_firmware, Wap361_firmware, Wap371_firmware | 5.3 | ||
2018-01-18 | CVE-2018-0098 | A vulnerability in the web-based management interface of Cisco WAP150 Wireless-AC/N Dual Radio Access Point with Power over Ethernet (PoE) and WAP361 Wireless-AC/N Dual Radio Wall Plate Access Point with PoE could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of... | Wap150_firmware, Wap361_firmware | 6.1 |