VendorsCiscoaironet_1850iany version
Vulnerabilities

Cisco Aironet 1850i any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2022-20695
Cisco Wireless LAN Controller Management Interface Authentication Bypass Vulnerability
Published 2022-04-15 · Modified
10.0EPSS 0.198
CVE-2017-3831
A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. The vulnerability is due to improper implementation of authentication for accessing certain web pages using the GUI interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface of the affected system. A successful exploit could allow the attacker to bypass authentication and perform unauthorized configuration changes or issue control commands to the affected device. This vulnerability affects Cisco Mobility Express 1800 Series Access Points running a software version prior to 8.2.110.0. Cisco Bug IDs: CSCuy68219.
Published 2017-03-15 · Modified
10.0EPSS 0.053
CVE-2020-3560
Cisco Aironet Access Points UDP Flooding Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.014
CVE-2020-3559
Cisco Aironet Access Point Authentication Flood Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.014
CVE-2017-3873
A vulnerability in the Plug-and-Play (PnP) subsystem of the Cisco Aironet 1800, 2800, and 3800 Series Access Points running a Lightweight Access Point (AP) or Mobility Express image could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges. The vulnerability is due to insufficient validation of PnP server responses. The PnP feature is only active while the device does not contain a configuration, such as a first time boot or after a factory reset has been issued. An attacker with the ability to respond to PnP configuration requests from the affected device can exploit the vulnerability by returning malicious PnP responses. If a Cisco Application Policy Infrastructure Controller - Enterprise Module (APIC-EM) is available on the network, the attacker would need to exploit the issue in the short window before a valid PnP response was received. If successful, the attacker could gain the ability to execute arbitrary code with root privileges on the underlying operating system of the device. Cisco has confirmed that the only vulnerable software version is 8.3.102.0. Cisco Bug IDs: CSCvb42386.
Published 2017-05-16 · Modified
7.9EPSS 0.007
CVE-2015-6320
The IP ingress packet handler on Cisco Aironet 1800 devices with software 8.1(112.3) and 8.1(112.4) allows remote attackers to cause a denial of service via a crafted header in an IP packet, aka Bug ID CSCuv63138.
Published 2016-01-15 · Modified
7.8EPSS 0.019
CVE-2016-1418
Cisco Aironet Access Point Software 8.2(100.0) on 1830e, 1830i, 1850e, 1850i, 2800, and 3800 access points allows local users to obtain Linux root access via crafted CLI command parameters, aka Bug ID CSCuy64037.
Published 2016-06-08 · Modified
7.8EPSS 0.004
CVE-2021-1419
Cisco Access Points SSH Management Privilege Escalation Vulnerability
Published 2021-09-23 · Modified
7.8EPSS 0.002
CVE-2015-6336
Cisco Aironet 1800 devices with software 7.2, 7.3, 7.4, 8.1(112.3), 8.1(112.4), and 8.1(15.14) have a default account, which makes it easier for remote attackers to obtain access via unspecified vectors, aka Bug ID CSCuw58062.
Published 2016-01-15 · Modified
7.5EPSS 0.014
CVE-2017-12281
A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of Cisco Aironet 1800, 2800, and 3800 Series Access Points could allow an unauthenticated, adjacent attacker to bypass authentication and connect to an affected device. The vulnerability exists because the affected device uses an incorrect default configuration setting of fail open when running in standalone mode. An attacker could exploit this vulnerability by attempting to connect to an affected device. A successful exploit could allow the attacker to bypass authentication and connect to the affected device. This vulnerability affects Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running a vulnerable software release and use WLAN configuration settings that include FlexConnect local switching and central authentication with MAC filtering. Cisco Bug IDs: CSCvd46314.
Published 2017-11-02 · Modified
7.5EPSS 0.007
CVE-2019-1834
Cisco Aironet Series Access Points Denial of Service Vulnerability
Published 2019-04-18 · Modified
7.4EPSS 0.006
CVE-2020-3552
Cisco Aironet Access Points Ethernet Wired Clients Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.005
CVE-2021-34740
Cisco Aironet Access Points WLAN Control Protocol Packet Buffer Leak Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2019-1829
Cisco Aironet Series Access Points Command Injection Vulnerability
Published 2019-04-18 · Modified
7.2EPSS 0.004
CVE-2019-1826
Cisco Aironet Series Access Points Quality of Service Denial of Service Vulnerability
Published 2019-04-18 · Modified
6.8EPSS 0.006
CVE-2022-20728
Cisco Access Points VLAN Bypass from Native VLAN Vulnerability
Published 2022-09-30 · Modified
4.7EPSS 0.003
CVE-2019-1835
Cisco Aironet Series Access Points Directory Traversal Vulnerability
Published 2019-04-18 · Modified
4.4EPSS 0.008