Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-15265


A vulnerability in the bridge protocol data unit (BPDU) forwarding functionality of Cisco Aironet Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an AP port to go into an error disabled state. The vulnerability occurs because BPDUs received from specific wireless clients are forwarded incorrectly. An attacker could exploit this vulnerability on the wireless network by sending a steady stream of crafted BPDU frames. A successful exploit could allow the attacker to cause a limited denial of service (DoS) attack because an AP port could go offline.


Published

2019-10-16T19:15:14.147

Last Modified

2024-11-21T04:28:19.460

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco aironet_1540_firmware < 8.5.151.0 Yes
Operating System cisco aironet_1540_firmware < 8.8.120.0 Yes
Operating System cisco aironet_1540_firmware < 8.9.100.0 Yes
Hardware cisco aironet_1540 - No
Operating System cisco aironet_1560_firmware < 8.5.151.0 Yes
Operating System cisco aironet_1560_firmware < 8.8.120.0 Yes
Operating System cisco aironet_1560_firmware < 8.9.100.0 Yes
Hardware cisco aironet_1560 - No
Operating System cisco aironet_1800_firmware < 8.5.151.0 Yes
Operating System cisco aironet_1800_firmware < 8.8.120.0 Yes
Operating System cisco aironet_1800_firmware < 8.9.100.0 Yes
Hardware cisco aironet_1800 - No
Operating System cisco aironet_2800_firmware < 8.5.151.0 Yes
Operating System cisco aironet_2800_firmware < 8.8.120.0 Yes
Operating System cisco aironet_2800_firmware < 8.9.100.0 Yes
Hardware cisco aironet_2800 - No
Operating System cisco aironet_3800_firmware < 8.5.151.0 Yes
Operating System cisco aironet_3800_firmware < 8.8.120.0 Yes
Operating System cisco aironet_3800_firmware < 8.9.100.0 Yes
Hardware cisco aironet_3800 - No

References