VendorsCiscoaironet_access_point_firmwareall versions
Vulnerabilities

Cisco Aironet Access Point Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2017-3834
A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express Software could allow an unauthenticated, remote attacker to take complete control of an affected device. The vulnerability is due to the existence of default credentials for an affected device that is running Cisco Mobility Express Software, regardless of whether the device is configured as a master, subordinate, or standalone access point. An attacker who has layer 3 connectivity to an affected device could use Secure Shell (SSH) to log in to the device with elevated privileges. A successful exploit could allow the attacker to take complete control of the device. This vulnerability affects Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points that are running an 8.2.x release of Cisco Mobility Express Software prior to Release 8.2.111.0, regardless of whether the device is configured as a master, subordinate, or standalone access point. Release 8.2 was the first release of Cisco Mobility Express Software for next generation Cisco Aironet Access Points. Cisco Bug IDs: CSCva50691.
Published 2017-04-06 · Modified
10.0EPSS 0.045
CVE-2017-3873
A vulnerability in the Plug-and-Play (PnP) subsystem of the Cisco Aironet 1800, 2800, and 3800 Series Access Points running a Lightweight Access Point (AP) or Mobility Express image could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges. The vulnerability is due to insufficient validation of PnP server responses. The PnP feature is only active while the device does not contain a configuration, such as a first time boot or after a factory reset has been issued. An attacker with the ability to respond to PnP configuration requests from the affected device can exploit the vulnerability by returning malicious PnP responses. If a Cisco Application Policy Infrastructure Controller - Enterprise Module (APIC-EM) is available on the network, the attacker would need to exploit the issue in the short window before a valid PnP response was received. If successful, the attacker could gain the ability to execute arbitrary code with root privileges on the underlying operating system of the device. Cisco has confirmed that the only vulnerable software version is 8.3.102.0. Cisco Bug IDs: CSCvb42386.
Published 2017-05-16 · Modified
7.9EPSS 0.007
CVE-2019-1834
Cisco Aironet Series Access Points Denial of Service Vulnerability
Published 2019-04-18 · Modified
7.4EPSS 0.006
CVE-2019-1829
Cisco Aironet Series Access Points Command Injection Vulnerability
Published 2019-04-18 · Modified
7.2EPSS 0.004
CVE-2019-1826
Cisco Aironet Series Access Points Quality of Service Denial of Service Vulnerability
Published 2019-04-18 · Modified
6.8EPSS 0.006
CVE-2019-1835
Cisco Aironet Series Access Points Directory Traversal Vulnerability
Published 2019-04-18 · Modified
4.4EPSS 0.008