CVE-2019-15265
Summary
| CVE | CVE-2019-15265 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-16 19:15:00 UTC |
| Updated | 2019-10-22 19:33:00 UTC |
| Description | A vulnerability in the bridge protocol data unit (BPDU) forwarding functionality of Cisco Aironet Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an AP port to go into an error disabled state. The vulnerability occurs because BPDUs received from specific wireless clients are forwarded incorrectly. An attacker could exploit this vulnerability on the wireless network by sending a steady stream of crafted BPDU frames. A successful exploit could allow the attacker to cause a limited denial of service (DoS) attack because an AP port could go offline. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Aironet 1540 | - | All | All | All |
| Hardware | Cisco | Aironet 1540 | - | All | All | All |
| Operating System | Cisco | Aironet 1540 Firmware | All | All | All | All |
| Operating System | Cisco | Aironet 1540 Firmware | All | All | All | All |
| Hardware | Cisco | Aironet 1560 | - | All | All | All |
| Hardware | Cisco | Aironet 1560 | - | All | All | All |
| Operating System | Cisco | Aironet 1560 Firmware | All | All | All | All |
| Operating System | Cisco | Aironet 1560 Firmware | All | All | All | All |
| Hardware | Cisco | Aironet 1800 | - | All | All | All |
| Hardware | Cisco | Aironet 1800 | - | All | All | All |
| Operating System | Cisco | Aironet 1800 Firmware | All | All | All | All |
| Operating System | Cisco | Aironet 1800 Firmware | All | All | All | All |
| Hardware | Cisco | Aironet 2800 | - | All | All | All |
| Hardware | Cisco | Aironet 2800 | - | All | All | All |
| Operating System | Cisco | Aironet 2800 Firmware | All | All | All | All |
| Operating System | Cisco | Aironet 2800 Firmware | All | All | All | All |
| Hardware | Cisco | Aironet 3800 | - | All | All | All |
| Hardware | Cisco | Aironet 3800 | - | All | All | All |
| Operating System | Cisco | Aironet 3800 Firmware | All | All | All | All |
| Operating System | Cisco | Aironet 3800 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Aironet Access Points Bridge Protocol Data Unit Port Disable Denial of Service Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.