// For flags

CVE-2019-1834

Cisco Aironet Series Access Points Denial of Service Vulnerability

Severity Score

6.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

A vulnerability in the internal packet processing of Cisco Aironet Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected AP if the switch interface where the AP is connected has port security configured. The vulnerability exists because the AP forwards some malformed wireless client packets outside of the Control and Provisioning of Wireless Access Points (CAPWAP) tunnel. An attacker could exploit this vulnerability by sending crafted wireless packets to an affected AP. A successful exploit could allow the attacker to trigger a security violation on the adjacent switch port, which could result in a DoS condition. Note: Though the Common Vulnerability Scoring System (CVSS) score corresponds to a High Security Impact Rating (SIR), this vulnerability is considered Medium because a workaround is available and exploitation requires a specific switch configuration. There are workarounds that address this vulnerability.

Una vulnerabilidad en el procesamiento interno de paquetes de Aironet Series Access Points (APs) de Cisco, podría permitir que un atacante no identificado localmente genere una condición de denegación de servicio (DoS) en un dispositivo AP afectado si la interfaz del conmutador donde está conectado el dispositivo AP tiene una seguridad de puerto configurada. La vulnerabilidad existe porque el AP corre en algunos paquetes del cliente de red inalámbrica malformados fuera del control y del aprovisionamiento del túnel de los puntos de acceso inalámbricos (CAPWAP). Un atacante podría aprovechar esta vulnerabilidad enviando paquetes inalámbricos creados a un dispositivo AP afectado. Una operación con éxito podría permitir al atacante desencadenar una violación de seguridad en el puerto del switch adyacente, lo que podría resultar en una condición de DoS. Nota: aunque la puntuación del sistema común de puntuación de vulnerabilidad (CVSS) corresponde a una clasificación de impacto de alta seguridad (SIR), esta vulnerabilidad se considera Media porque hay una solución disponible y la explotación requiere una configuración de conmutador específica. Hay soluciones que abordan esta vulnerabilidad.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2018-12-06 CVE Reserved
  • 2019-04-18 CVE Published
  • 2024-09-07 EPSS Updated
  • 2024-11-21 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.5 < 8.5.140.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.5 < 8.5.140.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542d
Search vendor "Cisco" for product "Aironet 1542d"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.5 < 8.5.140.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.5 < 8.5.140.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542i
Search vendor "Cisco" for product "Aironet 1542i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.5 < 8.5.140.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.5 < 8.5.140.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562d
Search vendor "Cisco" for product "Aironet 1562d"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.5 < 8.5.140.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.5 < 8.5.140.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562e
Search vendor "Cisco" for product "Aironet 1562e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.5 < 8.5.140.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.5 < 8.5.140.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562i
Search vendor "Cisco" for product "Aironet 1562i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.5 < 8.5.140.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.5 < 8.5.140.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1800i
Search vendor "Cisco" for product "Aironet 1800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.5 < 8.5.140.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.5 < 8.5.140.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800e
Search vendor "Cisco" for product "Aironet 2800e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.5 < 8.5.140.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.5 < 8.5.140.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800i
Search vendor "Cisco" for product "Aironet 2800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.5 < 8.5.140.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.5 < 8.5.140.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800e
Search vendor "Cisco" for product "Aironet 3800e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.5 < 8.5.140.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.5 < 8.5.140.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800i
Search vendor "Cisco" for product "Aironet 3800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.5 < 8.5.140.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.5 < 8.5.140.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800p
Search vendor "Cisco" for product "Aironet 3800p"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.6.101.0 < 8.8.111.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.6.101.0 < 8.8.111.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542d
Search vendor "Cisco" for product "Aironet 1542d"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.6.101.0 < 8.8.111.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.6.101.0 < 8.8.111.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542i
Search vendor "Cisco" for product "Aironet 1542i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.6.101.0 < 8.8.111.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.6.101.0 < 8.8.111.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562d
Search vendor "Cisco" for product "Aironet 1562d"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.6.101.0 < 8.8.111.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.6.101.0 < 8.8.111.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562e
Search vendor "Cisco" for product "Aironet 1562e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.6.101.0 < 8.8.111.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.6.101.0 < 8.8.111.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562i
Search vendor "Cisco" for product "Aironet 1562i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.6.101.0 < 8.8.111.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.6.101.0 < 8.8.111.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1800i
Search vendor "Cisco" for product "Aironet 1800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.6.101.0 < 8.8.111.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.6.101.0 < 8.8.111.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800e
Search vendor "Cisco" for product "Aironet 2800e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.6.101.0 < 8.8.111.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.6.101.0 < 8.8.111.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800i
Search vendor "Cisco" for product "Aironet 2800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.6.101.0 < 8.8.111.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.6.101.0 < 8.8.111.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800e
Search vendor "Cisco" for product "Aironet 3800e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.6.101.0 < 8.8.111.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.6.101.0 < 8.8.111.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800i
Search vendor "Cisco" for product "Aironet 3800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.6.101.0 < 8.8.111.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.6.101.0 < 8.8.111.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800p
Search vendor "Cisco" for product "Aironet 3800p"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.8.120.0 < 8.9.100.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.8.120.0 < 8.9.100.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542d
Search vendor "Cisco" for product "Aironet 1542d"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.8.120.0 < 8.9.100.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.8.120.0 < 8.9.100.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542i
Search vendor "Cisco" for product "Aironet 1542i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.8.120.0 < 8.9.100.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.8.120.0 < 8.9.100.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562d
Search vendor "Cisco" for product "Aironet 1562d"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.8.120.0 < 8.9.100.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.8.120.0 < 8.9.100.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562e
Search vendor "Cisco" for product "Aironet 1562e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.8.120.0 < 8.9.100.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.8.120.0 < 8.9.100.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562i
Search vendor "Cisco" for product "Aironet 1562i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.8.120.0 < 8.9.100.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.8.120.0 < 8.9.100.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1800i
Search vendor "Cisco" for product "Aironet 1800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.8.120.0 < 8.9.100.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.8.120.0 < 8.9.100.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800e
Search vendor "Cisco" for product "Aironet 2800e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.8.120.0 < 8.9.100.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.8.120.0 < 8.9.100.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800i
Search vendor "Cisco" for product "Aironet 2800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.8.120.0 < 8.9.100.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.8.120.0 < 8.9.100.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800e
Search vendor "Cisco" for product "Aironet 3800e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.8.120.0 < 8.9.100.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.8.120.0 < 8.9.100.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800i
Search vendor "Cisco" for product "Aironet 3800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
>= 8.8.120.0 < 8.9.100.0
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version " >= 8.8.120.0 < 8.9.100.0"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800p
Search vendor "Cisco" for product "Aironet 3800p"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.5\(131.0\)
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.5\(131.0\)"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1850e
Search vendor "Cisco" for product "Aironet 1850e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.5\(131.0\)
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.5\(131.0\)"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1850i
Search vendor "Cisco" for product "Aironet 1850i"
--
Safe