cbcvebase.

Cisco Aironet Access Point Software vulnerabilities

35 known vulnerabilities affecting cisco/cisco_aironet_access_point_software.

Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH15MEDIUM18

Vulnerabilities

Page 2 of 2
CVE-2019-1829P4MEDIUMCVSS 6.7v8.5(131.0)2019-04-18
CVE-2019-1829 [MEDIUM] CWE-16 CVE-2019-1829: A vulnerability in the CLI of Cisco Aironet Series Access Points (APs) could allow an authenticated, A vulnerability in the CLI of Cisco Aironet Series Access Points (APs) could allow an authenticated, local attacker to gain access to the underlying Linux operating system (OS) without the proper authentication. The attacker would need valid administrator device credentials. The vulnerability is due to improper validation of user-supplied input for cer
nvd
CVE-2019-1834P4MEDIUMCVSS 6.5v8.5(131.0)2019-04-18
CVE-2019-1834 [MEDIUM] CWE-20 CVE-2019-1834: A vulnerability in the internal packet processing of Cisco Aironet Series Access Points (APs) could A vulnerability in the internal packet processing of Cisco Aironet Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected AP if the switch interface where the AP is connected has port security configured. The vulnerability exists because the AP forwards some malformed wire
nvd
CVE-2022-20945P4MEDIUMCVSS 6.5vn/a2022-09-30
CVE-2022-20945 [MEDIUM] CWE-120 CVE-2022-20945: A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Poin A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain parameters within association request frames received
nvd
CVE-2023-20112P4MEDIUMCVSS 6.5vn/a2023-03-23
CVE-2023-20112 [MEDIUM] CWE-126 CVE-2023-20112: A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacke A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain parameters within 802.11 frames. An attacker could exploit this vulnerability by sending a wireless 802.11 associatio
nvd
CVE-2020-3260P4MEDIUMCVSS 6.5vn/a2020-04-15
CVE-2020-3260 [MEDIUM] CWE-399 CVE-2020-3260: A vulnerability in Cisco Aironet Series Access Points Software could allow an unauthenticated, adjac A vulnerability in Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper processing of client packets that are sent to an affected access point (AP). An attacker could exploit this vulnerability by sendin
nvd
CVE-2019-15265P4MEDIUMCVSS 6.5≥ unspecified, < n/a2019-10-16
CVE-2019-15265 [MEDIUM] CWE-20 CVE-2019-15265: A vulnerability in the bridge protocol data unit (BPDU) forwarding functionality of Cisco Aironet Ac A vulnerability in the bridge protocol data unit (BPDU) forwarding functionality of Cisco Aironet Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an AP port to go into an error disabled state. The vulnerability occurs because BPDUs received from specific wireless clients are forwarded incorrectly. An attacker could expl
nvd
CVE-2019-15264P4MEDIUMCVSS 6.5≥ unspecified, < n/a2019-10-16
CVE-2019-15264 [MEDIUM] CWE-400 CVE-2019-15264: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol implemen A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation of Cisco Aironet and Catalyst 9100 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to improper
nvd
CVE-2025-20364P4MEDIUMCVSS 4.3v16.10.1ev16.10.1+67 more2025-09-24
CVE-2025-20364 [MEDIUM] CWE-346 CVE-2025-20364: A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vulnerability is due to insufficient verification checks of incoming 802.11 action frames. An attacker could exploit thi
nvd
CVE-2023-20056P4MEDIUMCVSS 5.5vn/a2023-03-23
CVE-2023-20056 [MEDIUM] CWE-78 CVE-2023-20056: A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticat A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a devi
nvd
CVE-2022-20728P4MEDIUMCVSS 4.7vn/a2022-09-30
CVE-2022-20728 [MEDIUM] CWE-284 CVE-2022-20728: A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an u A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they
nvd
CVE-2019-1826P4MEDIUMCVSS 5.7v8.52019-04-18
CVE-2019-1826 [MEDIUM] CWE-20 CVE-2019-1826: A vulnerability in the quality of service (QoS) feature of Cisco Aironet Series Access Points (APs) A vulnerability in the quality of service (QoS) feature of Cisco Aironet Series Access Points (APs) could allow an authenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation on QoS fields within Wi-Fi frames by the affected device. An attacker could exploit t
nvd
CVE-2023-20268P4MEDIUMCVSS 4.7v8.3.135.0v8.3.140.0+161 more2023-09-27
CVE-2023-20268 [MEDIUM] CWE-400 CVE-2023-20268: A vulnerability in the packet processing functionality of Cisco access point (AP) software could all A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device. This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a s
nvd
CVE-2025-20365P4MEDIUMCVSS 4.3v16.10.1ev16.10.1+67 more2025-09-24
CVE-2025-20365 [MEDIUM] CWE-940 CVE-2025-20365: A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Softwa A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway on an affected device. This vulnerability is due to a logic error in the processing of IPv6 RA packets that are received from wireless clients. An attacker could exploit t
nvd
CVE-2019-1835P4MEDIUMCVSS 4.4v8.8v8.92019-04-18
CVE-2019-1835 [MEDIUM] CWE-22 CVE-2019-1835: A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP. The vulnerability is due to improper sanitization of user-supplied input in specific CLI commands. An attacker could exploit this vulnerability by accessing the CLI of an affected AP with administr
nvd
CVE-2021-1423P4MEDIUMCVSS 4.4vn/a2021-03-24
CVE-2021-1423 [MEDIUM] CWE-668 CVE-2021-1423: A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could all A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability by issuing a command with crafted a
nvd
Cisco Aironet Access Point Software vulnerabilities | cvebase