Cisco Aironet Access Point Software vulnerabilities
35 known vulnerabilities affecting cisco/cisco_aironet_access_point_software.
Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH15MEDIUM18
Vulnerabilities
Page 1 of 2
CVE-2024-20418P2CRITICALCVSS 10.0vN/A2024-11-06
CVE-2024-20418 [CRITICAL] CWE-77 CVE-2024-20418: A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software
A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with root privileges on the underlying operating system.
This vulnerability is due to improper valida
nvd
CVE-2019-15260P2CRITICALCVSS 9.8≥ unspecified, < n/a2019-10-16
CVE-2019-15260 [CRITICAL] CWE-284 CVE-2019-15260: A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote
A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access control for certain URLs on an affected device. An attacker could exploit this vulnerability by requesting specific
nvd
CVE-2020-3559P3HIGHCVSS 8.6vn/a2020-09-24
CVE-2020-3559 [HIGH] CWE-400 CVE-2020-3559: A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote a
A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper handling of clients that are trying to connect to the AP. An attacker could exploit this vulnerability by sending authentication requests from multiple clients to an affec
nvd
CVE-2019-15261P3HIGHCVSS 8.6≥ unspecified, < n/a2019-10-16
CVE-2019-15261 [HIGH] CWE-20 CVE-2019-15261: A vulnerability in the Point-to-Point Tunneling Protocol (PPTP) VPN packet processing functionality
A vulnerability in the Point-to-Point Tunneling Protocol (PPTP) VPN packet processing functionality in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Generic Routing Encapsulat
nvd
CVE-2024-20271P3HIGHCVSS 8.6v8.2.100.0v8.2.130.0+154 more2024-03-27
CVE-2024-20271 [HIGH] CWE-20 CVE-2024-20271: A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unaut
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this vulnerability by sending a crafted IPv4 pac
nvd
CVE-2021-1437P3HIGHCVSS 7.5vn/a2021-03-24
CVE-2021-1437 [HIGH] CWE-275 CVE-2021-1437: A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software co
A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial File Transfer Protocol (TFTP) configuration. An attacker could exploit this vulnerability by sen
nvd
CVE-2020-3560P3HIGHCVSS 8.6vn/a2020-09-24
CVE-2020-3560 [HIGH] CWE-400 CVE-2020-3560: A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker
A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specific packets. An attacker could exploit this vulnerability by sending a series of crafted UDP packets to a specific po
nvd
CVE-2023-20176P3HIGHCVSS 8.6v8.10.170.0v16.10.1e+41 more2023-09-27
CVE-2023-20176 [HIGH] CWE-400 CVE-2023-20176: A vulnerability in the networking component of Cisco access point (AP) software could allow an unaut
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service.
This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an affected device as a wireless client and sending a hi
nvd
CVE-2019-1654P3HIGHCVSS 7.8≥ unspecified, < 8.3.150.02019-04-17
CVE-2019-1654 [HIGH] CWE-255 CVE-2019-1654: A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access P
A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access Points (APs) running the Cisco AP-COS operating system could allow an authenticated, local attacker to access the development shell without proper authentication, which allows for root access to the underlying Linux OS. The attacker would need valid device
nvd
CVE-2022-20622P3HIGHCVSS 7.5vn/a2022-04-15
CVE-2022-20622 [HIGH] CWE-770 CVE-2022-20622: A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catal
A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device may experience a performance degradation in traffic processing or high CPU usa
nvd
CVE-2020-3262P3HIGHCVSS 7.5vn/a2020-04-15
CVE-2020-3262 [HIGH] CWE-20 CVE-2020-3262: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol handler
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol handler of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of CAPWAP packets. An attacker could expl
nvd
CVE-2019-1920P3HIGHCVSS 7.4≥ unspecified, < 8.8.100.02019-07-17
CVE-2019-1920 [HIGH] CWE-20 CVE-2019-1920: A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs)
A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling condition for client authentication requests sent to a targeted
nvd
CVE-2020-3552P3HIGHCVSS 7.4vn/a2020-09-24
CVE-2020-3552 [HIGH] CWE-476 CVE-2020-3552: A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could
A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by connecting as a wired client to the E
nvd
CVE-2021-1439P3HIGHCVSS 7.4vn/a2021-03-24
CVE-2021-1439 [HIGH] CWE-120 CVE-2021-1439: A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco Aironet Series Access Points So
A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of incoming mDNS traffic. An attacker could exploit this vulnerability
nvd
CVE-2024-20354P3HIGHCVSS 7.4vN/A2024-03-27
CVE-2024-20354 [HIGH] CWE-460 CVE-2024-20354: A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Soft
A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device.
This vulnerability is due to incomplete cleanup of resources when dropping certain malformed frames. An attacker could exploit th
nvd
CVE-2018-0441P4HIGHCVSS 7.4vn/a2018-10-17
CVE-2018-0441 [HIGH] CWE-400 CVE-2018-0441: A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software
A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a corruption of certain timer mechanisms triggered by specific roaming events. This corruption will eventual
nvd
CVE-2021-34740P4HIGHCVSS 7.4vn/a2021-09-23
CVE-2021-34740 [HIGH] CWE-401 CVE-2021-34740: A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP
A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect error handling when an affected device receives an unexpected
nvd
CVE-2023-20097P4MEDIUMCVSS 6.7vn/a2023-03-23
CVE-2023-20097 [MEDIUM] CWE-77 CVE-2023-20097: A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to
A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to an AP. An attacker with Administrator access to the CLI of the controller
nvd
CVE-2021-1449P4MEDIUMCVSS 6.7vn/a2021-03-24
CVE-2021-1449 [MEDIUM] CWE-284 CVE-2021-1449: A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, loca
A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code that manages system startup processes. An attacker could exploit this vulnerability by modifying a specific file that i
nvd
CVE-2024-20265P4MEDIUMCVSS 5.9v8.2.100.0v8.2.130.0+153 more2024-03-27
CVE-2024-20265 [MEDIUM] CWE-501 CVE-2024-20265: A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticat
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisco Secure Boot functionality and load a software image that has been tampered with on an affected device.
This vulnerability exists because unnecessary commands are available during boot time at the physical cons
nvd
1 / 2Next →