ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Cisco fixes serious flaws in enterprise-grade Catalyst and Aironet access points

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-15260
+2 in the same advisory: …15264 …15265
A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device w

A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access control for certain URLs on an affected device. An attacker could exploit this vulnerability by requesting specific URLs from an affected AP. An exploit could allow the attacker to gain access to the device with elevated privileges. While the attacker would not be granted access to all possible configuration options, it could allow the attacker to view sensitive information and replace some options with values of their choosing, including wireless network configuration. It would also allow the attacker to disable the AP, creating a denial of service (DoS) condition for clients associated with the AP.

NVD description · AI analysis pending
9.8
group max
3%
  • cisco aironet 1540 firmware
  • cisco aironet 1560 firmware
  • cisco aironet 1800 firmware
  • +1 more
CVE-2019-15261
A vulnerability in the Point-to-Point Tunneling Protocol (PPTP) VPN packet processing functionality in Cisco Aironet Access Points (APs) could allow an unauthen

A vulnerability in the Point-to-Point Tunneling Protocol (PPTP) VPN packet processing functionality in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Generic Routing Encapsulation (GRE) frames that pass through the data plane of an affected AP. An attacker could exploit this vulnerability by associating to a vulnerable AP, initiating a PPTP VPN connection to an arbitrary PPTP VPN server, and sending a malicious GRE frame through the data plane of the AP. A successful exploit could allow the attacker to cause an internal process of the targeted AP to crash, which in turn would cause the AP to reload. The AP reload would cause a DoS condition for clients that are associated with the AP.

NVD description · AI analysis pending
8.61%
  • cisco aironet 1810 firmware
  • cisco aironet 1830 firmware
  • cisco aironet 1850 firmware
CVE-2019-15262
A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to

A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the SSH process is not properly deleted when an SSH connection to the device is disconnected. An attacker could exploit this vulnerability by repeatedly opening SSH connections to an affected device. A successful exploit could allow the attacker to exhaust system resources by initiating multiple SSH connections to the device that are not effectively terminated, which could result in a DoS condition.

NVD description · AI analysis pending
7.51%
  • cisco 5520 wireless lan controller firmware
  • cisco 5508 wireless lan controller firmware
Full article282 words · extracted from helpnetsecurity.com · click to collapse

Cisco has released another batch of security updates, the most critical of which fixes a vulnerability that could allow unauthenticated, remote attackers to gain access to vulnerable Cisco Aironet wireless access points.

cisco Aironet vulnerabilities

Cisco Aironet APs are enterprise-grade access points used for branch offices, campuses, organizations of all sizes, enterprise and carrier-operator Wi-Fi deployments, and so on.

Cisco Aironet vulnerabilities

During the resolution of a Cisco TAC support case, the company’s technicians discovered a number of vulnerabilities affecting several series of Cisco Aironet APs and Catalyst APs.

The most crucial one is CVE-2019-15260, which could be exploited by attackers by requesting specific URLs from an affected AP and allow them to gain access to the device with elevated privileges.

“While the attacker would not be granted access to all possible configuration options, it could allow the attacker to view sensitive information and replace some options with values of their choosing, including wireless network configuration. It would also allow the attacker to disable the AP, creating a denial of service (DoS) condition for clients associated with the AP,” Cisco explained.

The other three – CVE-2019-15264, CVE-2019-15261 and CVE-2019-15265 – are less critical as the can “only” lead to DoS conditions.

There are no workarounds for any of the mentioned flaws, so administrators are advised to update to Cisco Aironet AP software releases 8.5.151.0 and later, 8.8.125.0 and later, and 8.9.111.0 and later to fix all of them. Release 8.10 is not vulnerable to any of them.

Finally, there is a separate DoS flaw that affects some of the Aironet devices: CVE-2019-15262 affects the SSH session management for Cisco Wireless LAN Controller (WLC) Software, and should also be fixed through a software upgrade.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/10/17/cisco-aironet-vulnerabilities/