Vulnerability Description
A vulnerability in the bridge protocol data unit (BPDU) forwarding functionality of Cisco Aironet Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an AP port to go into an error disabled state. The vulnerability occurs because BPDUs received from specific wireless clients are forwarded incorrectly. An attacker could exploit this vulnerability on the wireless network by sending a steady stream of crafted BPDU frames. A successful exploit could allow the attacker to cause a limited denial of service (DoS) attack because an AP port could go offline.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Aironet 1540 Firmware | < 8.5.151.0 |
| Cisco | Aironet 1540 | - |
| Cisco | Aironet 1560 Firmware | < 8.5.151.0 |
| Cisco | Aironet 1560 | - |
| Cisco | Aironet 1800 Firmware | < 8.5.151.0 |
| Cisco | Aironet 1800 | - |
| Cisco | Aironet 2800 Firmware | < 8.5.151.0 |
| Cisco | Aironet 2800 | - |
| Cisco | Aironet 3800 Firmware | < 8.5.151.0 |
| Cisco | Aironet 3800 | - |
Related Weaknesses (CWE)
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
FAQ
What is CVE-2019-15265?
CVE-2019-15265 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the bridge protocol data unit (BPDU) forwarding functionality of Cisco Aironet Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an AP port to go into a...
How severe is CVE-2019-15265?
CVE-2019-15265 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15265?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Aironet 1540 Firmware, Cisco Aironet 1540, Cisco Aironet 1560 Firmware, Cisco Aironet 1560, Cisco Aironet 1800 Firmware.