← Back

CVE-2019-1920

nvd nist
Published: Jul 17, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 4.0
Source: NVD

Description

A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling condition for client authentication requests sent to a targeted interface configured for FT. An attacker could exploit this vulnerability by sending crafted authentication request traffic to the targeted interface, causing the device to restart unexpectedly.

Affected (10)

4 products
Aironet 3700e Firmware
Aironet 3700i Firmware
Aironet 3700p Firmware
Access Points
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 15.3(3)jc14
Version 15.3(3)jd6
Running on/withPlatform Versions
Cisco
Aironet 3700e
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 15.3(3)jc14
Version 15.3(3)jd6
Running on/withPlatform Versions
Cisco
Aironet 3700i
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 15.3(3)jc14
Version 15.3(3)jd6
Running on/withPlatform Versions
Cisco
Aironet 3700p
All versions
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Before 8.2.170.0
From 8.3 to 8.3.150.0
From 8.4 to 8.5.131.0
From 8.6 to 8.8.100.0

References (4)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.