CVE-2019-1920
published 2019-07-17CVE-2019-1920: A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker…
PriorityP335high7.4CVSS 3.1
AVAACLPRNUINSCCNINAH
EPSS
0.80%
52.3th percentile
A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling condition for client authentication requests sent to a targeted interface configured for FT. An attacker could exploit this vulnerability by sending crafted authentication request traffic to the targeted interface, causing the device to restart unexpectedly.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | access_points | < 8.2.170.0 | 8.2.170.0 |
| cisco | access_points | >= 8.3 < 8.3.150.0 | 8.3.150.0 |
| cisco | access_points | >= 8.4 < 8.5.131.0 | 8.5.131.0 |
| cisco | access_points | >= 8.6 < 8.8.100.0 | 8.8.100.0 |
| cisco | aironet_3700e_firmware | — | — |
| cisco | aironet_3700e_firmware | — | — |
| cisco | aironet_3700i_firmware | — | — |
| cisco | aironet_3700i_firmware | — | — |
| cisco | aironet_3700p_firmware | — | — |
| cisco | aironet_3700p_firmware | — | — |
| cisco | cisco_aironet_access_point_software | >= unspecified < 8.8.100.0 | 8.8.100.0 |
| cisco | ios_access_points | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv3.07.4HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
vendor_cisco·2019-07-17·CVSS 7.4
CVE-2019-1920 [HIGH] CWE-20 Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface.
The vulnerability is due to a lack of complete error handling condition for client authentication requests sent to a targeted interface configured for FT. An attacker could exploit this vulnerability by sending crafted authentication request traffic to the targeted interface, causing the device to restart unexpectedly.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available a
Cisco
Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1920 Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
CVE-2019-1920: Cisco IOS Access Points Software 802.11r Fast Transition Denial of Service Vulnerability
A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling condition for client authentication requests sent to a targeted interface configured for FT. An attacker could exploit this vulnerability by sending crafted authentication request traffic to the targeted interface, causing the device to restart unexpectedly. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvg95745
GHSA
GHSA-4w9g-6vm8-cmqg: A vulnerability in the 802
ghsa_unreviewed·2022-05-24
CVE-2019-1920 [HIGH] CWE-20 GHSA-4w9g-6vm8-cmqg: A vulnerability in the 802
A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling condition for client authentication requests sent to a targeted interface configured for FT. An attacker could exploit this vulnerability by sending crafted authentication request traffic to the targeted interface, causing the device to restart unexpectedly.
No detection rules found.
Exploit-DB
Webmin 1.920 - Remote Code Execution
exploitdb·2019-08-19·CVSS 9.8
CVE-2019-15107 [CRITICAL] Webmin 1.920 - Remote Code Execution
Webmin 1.920 - Remote Code Execution
---
#!/bin/sh
#
# CVE-2019-15107 Webmin Unauhenticated Remote Command Execution
# based on Metasploit module https://www.exploit-db.com/exploits/47230
# Original advisory: https://pentest.com.tr/exploits/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.html
# Alternative advisory (spanish): https://blog.nivel4.com/noticias/vulnerabilidad-de-ejecucion-de-comandos-remotos-en-webmin
#
# Fernando A. Lagos B. (Zerial)
# https://blog.zerial.org
# https://blog.nivel4.com
#
# The script sends a flag by a echo command then grep it. If match, target is vulnerable.
#
# Usage: sh CVE-2019-15107.sh https://target:port
# Example: sh CVE-2019-15107.sh https://localhost:10000
# output: Testing for RCE (CVE-2019-15107) on https://localhost:10000: VULNERABLE
Nuclei
Webmin <= 1.920 - Unauthenticated Remote Command Execution
nuclei·CVSS 9.8
CVE-2019-15107 [CRITICAL] Webmin <= 1.920 - Unauthenticated Remote Command Execution
Webmin <= 1.920 - Unauthenticated Remote Command Execution
Webmin <=1.920. is vulnerable to an unauthenticated remote command execution via the parameter 'old' in password_change.cgi.
Template:
id: CVE-2019-15107
info:
name: Webmin <= 1.920 - Unauthenticated Remote Command Execution
author: bp0lr
severity: critical
description: Webmin <=1.920. is vulnerable to an unauthenticated remote command execution via the parameter 'old' in password_change.cgi.
impact: |
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands with root privileges.
remediation: |
Upgrade to Webmin version 1.930 or later to mitigate this vulnerability.
reference:
- https://pentest.com.tr/exploits/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.html
- https://n
No writeups or analysis indexed.
2019-07-17
Published