First published: Wed Oct 16 2019(Updated: )
A vulnerability in the bridge protocol data unit (BPDU) forwarding functionality of Cisco Aironet Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an AP port to go into an error disabled state. The vulnerability occurs because BPDUs received from specific wireless clients are forwarded incorrectly. An attacker could exploit this vulnerability on the wireless network by sending a steady stream of crafted BPDU frames. A successful exploit could allow the attacker to cause a limited denial of service (DoS) attack because an AP port could go offline.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Aironet 1540 Firmware | <8.5.151.0 | |
Cisco Aironet 1540 Firmware | >=8.6<8.8.120.0 | |
Cisco Aironet 1540 Firmware | >=8.8.125.0<8.9.100.0 | |
Cisco Aironet 1540 | ||
Cisco Aironet 1560 Firmware | <8.5.151.0 | |
Cisco Aironet 1560 Firmware | >=8.6<8.8.120.0 | |
Cisco Aironet 1560 Firmware | >=8.8.125.0<8.9.100.0 | |
Cisco Aironet 1560 | ||
Cisco Aironet 1800 Firmware | <8.5.151.0 | |
Cisco Aironet 1800 Firmware | >=8.6<8.8.120.0 | |
Cisco Aironet 1800 Firmware | >=8.8.125.0<8.9.100.0 | |
Cisco Aironet 1800 | ||
Cisco Aironet 2800 Firmware | <8.5.151.0 | |
Cisco Aironet 2800 Firmware | >=8.6<8.8.120.0 | |
Cisco Aironet 2800 Firmware | >=8.8.125.0<8.9.100.0 | |
Cisco Aironet 2800 | ||
Cisco Aironet 3800 Firmware | <8.5.151.0 | |
Cisco Aironet 3800 Firmware | >=8.6<8.8.120.0 | |
Cisco Aironet 3800 Firmware | >=8.8.125.0<8.9.100.0 | |
Cisco Aironet 3800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-15265.
The severity of CVE-2019-15265 is high.
Cisco Aironet 1540, Cisco Aironet 1560, Cisco Aironet 1800, and Cisco Aironet 2800 are affected by CVE-2019-15265.
CVE-2019-15265 could allow an unauthenticated, adjacent attacker to cause an AP port to go into an error disabled state.
Yes, there is a fix available for CVE-2019-15265. Please refer to the Cisco Security Advisory for more information.