CVE-2019-1920

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/07/2019
Last modified:
16/10/2020

Description

A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling condition for client authentication requests sent to a targeted interface configured for FT. An attacker could exploit this vulnerability by sending crafted authentication request traffic to the targeted interface, causing the device to restart unexpectedly.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:aironet_3700e_firmware:15.3\(3\)jc14:*:*:*:*:*:*:*
cpe:2.3:o:cisco:aironet_3700e_firmware:15.3\(3\)jd6:*:*:*:*:*:*:*
cpe:2.3:h:cisco:aironet_3700e:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:aironet_3700i_firmware:15.3\(3\)jc14:*:*:*:*:*:*:*
cpe:2.3:o:cisco:aironet_3700i_firmware:15.3\(3\)jd6:*:*:*:*:*:*:*
cpe:2.3:h:cisco:aironet_3700i:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:aironet_3700p_firmware:15.3\(3\)jc14:*:*:*:*:*:*:*
cpe:2.3:o:cisco:aironet_3700p_firmware:15.3\(3\)jd6:*:*:*:*:*:*:*
cpe:2.3:h:cisco:aironet_3700p:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:access_points:*:*:*:*:*:*:*:* 8.2.170.0 (excluding)
cpe:2.3:o:cisco:access_points:*:*:*:*:*:*:*:* 8.3 (including) 8.3.150.0 (excluding)
cpe:2.3:o:cisco:access_points:*:*:*:*:*:*:*:* 8.4 (including) 8.5.131.0 (excluding)
cpe:2.3:o:cisco:access_points:*:*:*:*:*:*:*:* 8.6 (including) 8.8.100.0 (excluding)