Cisco Aironet Access Point Software vulnerabilities

35 known vulnerabilities affecting cisco/cisco_aironet_access_point_software.

Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH15MEDIUM18

Vulnerabilities

Page 2 of 2
CVE-2020-3552HIGHCVSS 7.4vn/a2020-09-24
CVE-2020-3552 [HIGH] CWE-476 CVE-2020-3552: A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by connecting as a wired client to the E
cvelistv5nvd
CVE-2020-3559HIGHCVSS 8.6vn/a2020-09-24
CVE-2020-3559 [HIGH] CWE-400 CVE-2020-3559: A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote a A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper handling of clients that are trying to connect to the AP. An attacker could exploit this vulnerability by sending authentication requests from multiple clients to an affec
cvelistv5nvd
CVE-2020-3262HIGHCVSS 7.5vn/a2020-04-15
CVE-2020-3262 [HIGH] CWE-20 CVE-2020-3262: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol handler A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol handler of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of CAPWAP packets. An attacker could expl
cvelistv5nvd
CVE-2020-3260MEDIUMCVSS 6.5vn/a2020-04-15
CVE-2020-3260 [MEDIUM] CWE-399 CVE-2020-3260: A vulnerability in Cisco Aironet Series Access Points Software could allow an unauthenticated, adjac A vulnerability in Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper processing of client packets that are sent to an affected access point (AP). An attacker could exploit this vulnerability by sendin
cvelistv5nvd
CVE-2019-15260CRITICALCVSS 9.8≥ unspecified, < n/a2019-10-16
CVE-2019-15260 [CRITICAL] CWE-284 CVE-2019-15260: A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access control for certain URLs on an affected device. An attacker could exploit this vulnerability by requesting specific
cvelistv5nvd
CVE-2019-15261HIGHCVSS 8.6≥ unspecified, < n/a2019-10-16
CVE-2019-15261 [HIGH] CWE-20 CVE-2019-15261: A vulnerability in the Point-to-Point Tunneling Protocol (PPTP) VPN packet processing functionality A vulnerability in the Point-to-Point Tunneling Protocol (PPTP) VPN packet processing functionality in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Generic Routing Encapsulat
cvelistv5nvd
CVE-2019-15265MEDIUMCVSS 6.5≥ unspecified, < n/a2019-10-16
CVE-2019-15265 [MEDIUM] CWE-20 CVE-2019-15265: A vulnerability in the bridge protocol data unit (BPDU) forwarding functionality of Cisco Aironet Ac A vulnerability in the bridge protocol data unit (BPDU) forwarding functionality of Cisco Aironet Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an AP port to go into an error disabled state. The vulnerability occurs because BPDUs received from specific wireless clients are forwarded incorrectly. An attacker could expl
cvelistv5nvd
CVE-2019-15264MEDIUMCVSS 6.5≥ unspecified, < n/a2019-10-16
CVE-2019-15264 [MEDIUM] CWE-400 CVE-2019-15264: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol implemen A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation of Cisco Aironet and Catalyst 9100 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to improper
cvelistv5nvd
CVE-2019-1920HIGHCVSS 7.4≥ unspecified, < 8.8.100.02019-07-17
CVE-2019-1920 [HIGH] CWE-20 CVE-2019-1920: A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling condition for client authentication requests sent to a targeted
cvelistv5nvd
CVE-2019-1834MEDIUMCVSS 6.5v8.5(131.0)2019-04-18
CVE-2019-1834 [MEDIUM] CWE-20 CVE-2019-1834: A vulnerability in the internal packet processing of Cisco Aironet Series Access Points (APs) could A vulnerability in the internal packet processing of Cisco Aironet Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected AP if the switch interface where the AP is connected has port security configured. The vulnerability exists because the AP forwards some malformed wire
cvelistv5nvd
CVE-2019-1835MEDIUMCVSS 4.4v8.8v8.92019-04-18
CVE-2019-1835 [MEDIUM] CWE-22 CVE-2019-1835: A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP. The vulnerability is due to improper sanitization of user-supplied input in specific CLI commands. An attacker could exploit this vulnerability by accessing the CLI of an affected AP with administr
cvelistv5nvd
CVE-2019-1829MEDIUMCVSS 6.7v8.5(131.0)2019-04-18
CVE-2019-1829 [MEDIUM] CWE-16 CVE-2019-1829: A vulnerability in the CLI of Cisco Aironet Series Access Points (APs) could allow an authenticated, A vulnerability in the CLI of Cisco Aironet Series Access Points (APs) could allow an authenticated, local attacker to gain access to the underlying Linux operating system (OS) without the proper authentication. The attacker would need valid administrator device credentials. The vulnerability is due to improper validation of user-supplied input for cer
cvelistv5nvd
CVE-2019-1826MEDIUMCVSS 5.7v8.52019-04-18
CVE-2019-1826 [MEDIUM] CWE-20 CVE-2019-1826: A vulnerability in the quality of service (QoS) feature of Cisco Aironet Series Access Points (APs) A vulnerability in the quality of service (QoS) feature of Cisco Aironet Series Access Points (APs) could allow an authenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation on QoS fields within Wi-Fi frames by the affected device. An attacker could exploit t
cvelistv5nvd
CVE-2019-1654HIGHCVSS 7.8≥ unspecified, < 8.3.150.02019-04-17
CVE-2019-1654 [HIGH] CWE-255 CVE-2019-1654: A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access P A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access Points (APs) running the Cisco AP-COS operating system could allow an authenticated, local attacker to access the development shell without proper authentication, which allows for root access to the underlying Linux OS. The attacker would need valid device
cvelistv5nvd
CVE-2018-0441HIGHCVSS 7.4vn/a2018-10-17
CVE-2018-0441 [HIGH] CWE-400 CVE-2018-0441: A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a corruption of certain timer mechanisms triggered by specific roaming events. This corruption will eventual
cvelistv5nvd
Cisco Aironet Access Point Software vulnerabilities | cvebase