Cisco Aironet Access Points contain a flaw that may allow a remote denial of service. The issue is triggered when an attacker sends many spoofed ARP messages to the management interface of the AP, adding entries to the ARP table until the memory is exhausted, and will result in loss of availability for the AP until it is restarted.
Classification
Location:
Remote/Network Access Required
Attack Type:
Denial of Service
Impact:
Loss of Availability
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Upgrade to IOS version 12.3-7-JA2 or higher, as it has been reported to fix this vulnerability. In addition to the software upgrade, a configuration change is necessary: add the command L2-FILTER BLOCK-ARP to each radio interface.
It is also possible to correct the flaw by implementing the following workaround(s): Use VLANs to isolate wireless clients from the Access Point (AP) management interface.