← Back

CVE-2019-1834

nvd nist
Published: Apr 18, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in the internal packet processing of Cisco Aironet Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected AP if the switch interface where the AP is connected has port security configured. The vulnerability exists because the AP forwards some malformed wireless client packets outside of the Control and Provisioning of Wireless Access Points (CAPWAP) tunnel. An attacker could exploit this vulnerability by sending crafted wireless packets to an affected AP. A successful exploit could allow the attacker to trigger a security violation on the adjacent switch port, which could result in a DoS condition. Note: Though the Common Vulnerability Scoring System (CVSS) score corresponds to a High Security Impact Rating (SIR), this vulnerability is considered Medium because a workaround is available and exploitation requires a specific switch configuration. There are workarounds that address this vulnerability.

Affected (4)

1 product
Aironet Access Point Firmware
Configuration A
3 vulnerable · 11 platform
Vulnerable SoftwareAffected Versions
Cisco
From 8.5 to 8.5.140.0
From 8.6.101.0 to 8.8.111.0
From 8.8.120.0 to 8.9.100.0
Running on/withPlatform Versions
Cisco
Aironet 1542d
All versions
Cisco
Aironet 1542i
All versions
Cisco
Aironet 1562d
All versions
Cisco
Aironet 1562e
All versions
Cisco
Aironet 1562i
All versions
Cisco
Aironet 1800i
All versions
Cisco
Aironet 2800e
All versions
Cisco
Aironet 2800i
All versions
Cisco
Aironet 3800e
All versions
Cisco
Aironet 3800i
All versions
Cisco
Aironet 3800p
All versions
Configuration B
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 8.5(131.0)
Running on/withPlatform Versions
Cisco
Aironet 1850e
All versions
Cisco
Aironet 1850i
All versions

References (4)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.