Cisco Catalyst 9115AXI/AXE, 9120AXI/AXE/AXP, 9130AXI/AXE and 9105AXI/AXW Wireless LAN Access Points
Caveat: When installed, initialized and configured as specified in the Section 3 of Security Policy.
Certificate
| Certificate number | 4278 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Cisco Systems, Inc. · website |
| Hardware versions | 9115AXI, 9115AXE, 9120AXI, 9120AXE, 9120AXP, 9130AXI, 9130AXE, 9105AXI and 9105AXW with FIPS Kit: AIR-AP-FIPSKIT= |
| Firmware versions | AireOS 8.10MR3 and IOS-XE 17.3 |
Module description
Cisco Catalyst Series Wireless Access Points provide highly secure and reliable wireless connections for both indoor and outdoor environments.
Security level exceptions
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | C788, C1870, C1872 |
| CVL | C788, C1870, C1872 |
| DRBG | C788, C1870, C1872 |
| ECDSA | C788, C1870, C1872 |
| HMAC | C788, C1870, C1872 |
| KAS-SSC | vendor affirmed |
| KBKDF | C788, C1870, C1872 |
| KTS | |
| KTS | |
| RSA | C788, C1870, C1872, C1915, C1916 |
| SHS | C788, C1870, C1872, C1915, C1916 |
Allowed algorithms
NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-08-15 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2022-08-15
Known CVEs in this module family (heuristic match)
Name-based association with the module's product family, not a statement about the validated boundary. See methodology.
| CVE | CVSS | Severity |
|---|---|---|
| CVE-2007-1467 | 3.5 | LOW |