Vulnslist

find the latest Cisco vulnerabilities

Cisco Aironet Series Access Points Denial of Service Vulnerability

cisco-sa-20190417-air-ap-dos · Medium · Published · Updated

A vulnerability in the internal packet processing of Cisco Aironet Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected AP if the switch interface where the AP is connected has port security configured. The vulnerability exists because the AP forwards some malformed wireless client packets outside of the Control and Provisioning of Wireless Access Points (CAPWAP) tunnel. An attacker could exploit this vulnerability by sending crafted wireless packets to an affected AP. A successful exploit could allow the attacker to trigger a security violation on the adjacent switch port, which could result in a DoS condition. Note: Though the Common Vulnerability Scoring System (CVSS) score corresponds to a High Security Impact Rating (SIR), this vulnerability is considered Medium because a workaround is available and exploitation requires a specific switch configuration. There are workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190417-air-ap-dos

Workarounds

Administrators can configure the switch interface with port security to learn only one MAC address (the switch learns the AP MAC address during AP bootup) and, in case of a security violation, to drop any new learned MAC addresses. Using the CLI, configure the security violation mode to either protect or restrict, as in the following example:

# configuration terminal
# interface interface_id # switchport port-security violation {protect | restrict}

Note: CLI commands may vary slightly by switch model.

CVEsCVE-2019-1834
Cisco Bug IDsCSCvj96316, CSCvm97169, CSCvq46817
CVSS ScoreBase 7.4
Base 7.4 CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Aironet Access Point Software

Related Products

Product CVE Evidence
Cisco Aironet Access Point Software CVE-2019-1834 Cisco OpenVuln