CVE-2019-1835: Cisco Aironet Series Access Points Directory Traversal Vulnerability
A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP. The vulnerability is due to improper sanitization of user-supplied input in specific CLI commands. An attacker could exploit this vulnerability by accessing the CLI of an affected AP with administrator privileges and issuing crafted commands that result in directory traversal. A successful exploit could allow the attacker to view system files on the affected device, which could contain sensitive information. Software versions 8.8 and 8.9 are affected.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Cisco Aironet Access Points (APs) vulnerability?
The vulnerability ID of this Cisco Aironet Access Points (APs) vulnerability is CVE-2019-1835.
What is the severity level of CVE-2019-1835?
The severity level of CVE-2019-1835 is medium with a score of 4.4.
How can an attacker exploit CVE-2019-1835?
An attacker can exploit CVE-2019-1835 by accessing sensitive information stored in an AP through improper sanitization of user-supplied input in specific CLI commands.
What is the affected software for CVE-2019-1835?
The affected software for CVE-2019-1835 is Cisco Aironet Access Point Firmware versions 8.8 and 8.9.
Where can I find more information about CVE-2019-1835?
You can find more information about CVE-2019-1835 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/108001) and [Cisco Security Advisory](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190417-air-ap-traversal).