CVE-2019-15260
published 2019-10-16CVE-2019-15260: A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.99%
85.9th percentile
A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access control for certain URLs on an affected device. An attacker could exploit this vulnerability by requesting specific URLs from an affected AP. An exploit could allow the attacker to gain access to the device with elevated privileges. While the attacker would not be granted access to all possible configuration options, it could allow the attacker to view sensitive information and replace some options with values of their choosing, including wireless network configuration. It would also allow the attacker to disable the AP, creating a denial of service (DoS) condition for clients associated with the AP.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | aironet_1540_firmware | >= 8.5 < 8.5.151.0 | 8.5.151.0 |
| cisco | aironet_1540_firmware | >= 8.8 < 8.8.120.0 | 8.8.120.0 |
| cisco | aironet_1560_firmware | >= 8.5 < 8.5.151.0 | 8.5.151.0 |
| cisco | aironet_1560_firmware | >= 8.8 < 8.8.120.0 | 8.8.120.0 |
| cisco | aironet_1800_firmware | >= 8.5 < 8.5.151.0 | 8.5.151.0 |
| cisco | aironet_1800_firmware | >= 8.8 < 8.8.120.0 | 8.8.120.0 |
| cisco | aironet_2800_firmware | >= 8.5 < 8.5.151.0 | 8.5.151.0 |
| cisco | aironet_2800_firmware | >= 8.8 < 8.8.120.0 | 8.8.120.0 |
| cisco | aironet_3800_firmware | >= 8.5 < 8.5.151.0 | 8.5.151.0 |
| cisco | aironet_3800_firmware | >= 8.8 < 8.8.120.0 | 8.8.120.0 |
| cisco | aironet_4800_firmware | >= 8.5 < 8.5.151.0 | 8.5.151.0 |
| cisco | aironet_4800_firmware | >= 8.8 < 8.8.120.0 | 8.8.120.0 |
| cisco | aironet_access_points_unauthorized_access | — | — |
| cisco | cisco_aironet_access_point_software | >= unspecified < n/a | n/a |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit involves requesting specific URLs from an affected Cisco Aironet AP that bypass access control and grant elevated privileges — monitor HTTP/HTTPS requests to the AP's management interface for access to restricted URL paths without authentication ↗
- →The vulnerability is rooted in insufficient access control for certain URLs — detection should focus on unauthenticated requests to sensitive management URLs on Cisco Aironet APs (e.g., configuration or admin endpoints) from external/untrusted sources ↗
- →Successful exploitation may result in wireless network configuration changes or AP being disabled — alert on unexpected configuration modifications or AP going offline (DoS indicator) ↗
- ·Cisco internal bug ID for this vulnerability is CSCvm54888 — useful for cross-referencing vendor patch notes and affected version lists ↗
- ·No workarounds exist for this vulnerability; only patching resolves it — unpatched Cisco Aironet APs remain fully exposed to unauthenticated remote exploitation ↗
- ·The attacker does not gain access to all configuration options, but can still read sensitive data and overwrite select settings including wireless network configuration ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Aironet Access Points Unauthorized Access Vulnerability
vendor_cisco·2019-10-16·CVSS 9.8
CVE-2019-15260 [CRITICAL] CWE-284 Cisco Aironet Access Points Unauthorized Access Vulnerability
Cisco Aironet Access Points Unauthorized Access Vulnerability
A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges.
The vulnerability is due to insufficient access control for certain URLs on an affected device. An attacker could exploit this vulnerability by requesting specific URLs from an affected AP. An exploit could allow the attacker to gain access to the device with elevated privileges. While the attacker would not be granted access to all possible configuration options, it could allow the attacker to view sensitive information and replace some options with values of their choosing, including wireless network configuration. It would also allow the attac
Cisco
Cisco Aironet Access Points Unauthorized Access Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-15260 Cisco Aironet Access Points Unauthorized Access Vulnerability
CVE-2019-15260: Cisco Aironet Access Points Unauthorized Access Vulnerability
A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access control for certain URLs on an affected device. An attacker could exploit this vulnerability by requesting specific URLs from an affected AP. An exploit could allow the attacker to gain access to the device with elevated privileges. While the attacker would not be granted access to all possible configuration options, it could allow the attacker to view sensitive information and replace some options with values of their choosing, including wireless network configuration. It would also
GHSA
GHSA-rfr3-7m2c-w5hg: A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targete
ghsa_unreviewed·2022-05-24
CVE-2019-15260 [CRITICAL] GHSA-rfr3-7m2c-w5hg: A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targete
A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access control for certain URLs on an affected device. An attacker could exploit this vulnerability by requesting specific URLs from an affected AP. An exploit could allow the attacker to gain access to the device with elevated privileges. While the attacker would not be granted access to all possible configuration options, it could allow the attacker to view sensitive information and replace some options with values of their choosing, including wireless network configuration. It would also allow the attacker to disable the AP, creating a denial of service (DoS) condi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-10-16
Published