6.5
CVSSv3

CVE-2019-15264

Published: 16/10/2019 Updated: 22/10/2019
CVSS v2 Base Score: 6.1 | Impact Score: 6.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 543
Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation of Cisco Aironet and Catalyst 9100 Access Points (APs) could allow an unauthenticated, adjacent malicious user to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to improper resource management during CAPWAP message processing. An attacker could exploit this vulnerability by sending a high volume of legitimate wireless management frames within a short time to an affected device. A successful exploit could allow the malicious user to cause a device to restart unexpectedly, resulting in a DoS condition for clients associated with the AP.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco aironet_1540_firmware -

cisco aironet_1560_firmware -

cisco aironet_1850_firmware 8.10\\(1.139\\)

cisco aironet_1850_firmware 8.9\\(1.249\\)

cisco aironet_1850_firmware 8.9\\(104.24\\)

cisco aironet_1850_firmware 8.9\\(4.41\\)

cisco aironet_1850_firmware 8.9\\(4.49\\)

cisco aironet_1850_firmware 8.9\\(4.55\\)

cisco aironet_1850_firmware 8.9\\(4.58\\)

cisco aironet_1850_firmware 8.10\\(1.146\\)

cisco aironet_1850_firmware 8.9\\(1.255\\)

cisco aironet_1850_firmware 8.9\\(4.28\\)

cisco aironet_1850_firmware -

cisco aironet_2800_firmware -

cisco aironet_3800_firmware -

cisco aironet_4800_firmware -

cisco catalyst_9100_firmware -

Vendor Advisories

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation of Cisco Aironet and Catalyst 9100 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition The vulnerability is due to imprope ...