First published: Wed Jul 17 2019(Updated: )
A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling condition for client authentication requests sent to a targeted interface configured for FT. An attacker could exploit this vulnerability by sending crafted authentication request traffic to the targeted interface, causing the device to restart unexpectedly.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Aironet 3700e Firmware | =15.3\(3\)jc14 | |
Cisco Aironet 3700e Firmware | =15.3\(3\)jd6 | |
Cisco Aironet 3700e | ||
Cisco Aironet 3700i Firmware | =15.3\(3\)jc14 | |
Cisco Aironet 3700i Firmware | =15.3\(3\)jd6 | |
Cisco Aironet 3700i | ||
Cisco Aironet 3700p Firmware | =15.3\(3\)jc14 | |
Cisco Aironet 3700p Firmware | =15.3\(3\)jd6 | |
Cisco Aironet 3700p | ||
Cisco Access Points | <8.2.170.0 | |
Cisco Access Points | >=8.3<8.3.150.0 | |
Cisco Access Points | >=8.4<8.5.131.0 | |
Cisco Access Points | >=8.6<8.8.100.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1920 is a vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software that could allow a denial of service (DoS) attack.
Cisco Aironet 3700e Firmware versions 15.3(3)jc14 and 15.3(3)jd6 are affected by CVE-2019-1920.
Cisco Aironet 3700i Firmware versions 15.3(3)jc14 and 15.3(3)jd6 are affected by CVE-2019-1920.
Cisco Aironet 3700p Firmware versions 15.3(3)jc14 and 15.3(3)jd6 are affected by CVE-2019-1920.
CVE-2019-1920 has a severity rating of 7.4 (high).
To mitigate the vulnerability, Cisco recommends upgrading to a fixed software release or disabling the 802.11r feature on affected devices.