// For flags

CVE-2019-1835

Cisco Aironet Series Access Points Directory Traversal Vulnerability

Severity Score

4.4
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP. The vulnerability is due to improper sanitization of user-supplied input in specific CLI commands. An attacker could exploit this vulnerability by accessing the CLI of an affected AP with administrator privileges and issuing crafted commands that result in directory traversal. A successful exploit could allow the attacker to view system files on the affected device, which could contain sensitive information. Software versions 8.8 and 8.9 are affected.

Una vulnerabilidad en la CLI de Aironet Access Points (APs) de Cisco, podría permitir que un atacante identificado y local acceda a información confidencial almacenada en un dispositivo AP. La vulnerabilidad se debe al saneamiento inadecuado de la entrada proporcionada por el usuario en comandos específicos de la CLI. Un atacante podría aprovechar esta vulnerabilidad accediendo a la CLI de un dispositivo AP afectado con privilegios de administrador y emitiendo comandos creados que resulten en el salto del directorio (directory traversal). Una operación con éxito podría permitir al atacante ver los archivos del sistema en el dispositivo afectado, que podría contener información confidencial. Las versiones de Software 8.8 y 8.9 se ven afectadas.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-12-06 CVE Reserved
  • 2019-04-18 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.8
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.8"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542d
Search vendor "Cisco" for product "Aironet 1542d"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.8
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.8"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542i
Search vendor "Cisco" for product "Aironet 1542i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.8
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.8"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562d
Search vendor "Cisco" for product "Aironet 1562d"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.8
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.8"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562e
Search vendor "Cisco" for product "Aironet 1562e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.8
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.8"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562i
Search vendor "Cisco" for product "Aironet 1562i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.8
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.8"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1800i
Search vendor "Cisco" for product "Aironet 1800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.8
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.8"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1850e
Search vendor "Cisco" for product "Aironet 1850e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.8
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.8"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1850i
Search vendor "Cisco" for product "Aironet 1850i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.8
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.8"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800e
Search vendor "Cisco" for product "Aironet 2800e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.8
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.8"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800i
Search vendor "Cisco" for product "Aironet 2800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.8
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.8"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800e
Search vendor "Cisco" for product "Aironet 3800e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.8
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.8"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800i
Search vendor "Cisco" for product "Aironet 3800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.8
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.8"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800p
Search vendor "Cisco" for product "Aironet 3800p"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.9
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.9"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542d
Search vendor "Cisco" for product "Aironet 1542d"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.9
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.9"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1542i
Search vendor "Cisco" for product "Aironet 1542i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.9
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.9"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562d
Search vendor "Cisco" for product "Aironet 1562d"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.9
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.9"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562e
Search vendor "Cisco" for product "Aironet 1562e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.9
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.9"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1562i
Search vendor "Cisco" for product "Aironet 1562i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.9
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.9"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1800i
Search vendor "Cisco" for product "Aironet 1800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.9
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.9"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1850e
Search vendor "Cisco" for product "Aironet 1850e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.9
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.9"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 1850i
Search vendor "Cisco" for product "Aironet 1850i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.9
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.9"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800e
Search vendor "Cisco" for product "Aironet 2800e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.9
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.9"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 2800i
Search vendor "Cisco" for product "Aironet 2800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.9
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.9"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800e
Search vendor "Cisco" for product "Aironet 3800e"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.9
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.9"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800i
Search vendor "Cisco" for product "Aironet 3800i"
--
Safe
Cisco
Search vendor "Cisco"
Aironet Access Point Firmware
Search vendor "Cisco" for product "Aironet Access Point Firmware"
8.9
Search vendor "Cisco" for product "Aironet Access Point Firmware" and version "8.9"
-
Affected
in Cisco
Search vendor "Cisco"
Aironet 3800p
Search vendor "Cisco" for product "Aironet 3800p"
--
Safe