MEDIUM · 4.4

CVE-2019-1835

A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP. The vulnerability is due to improper sanit...

Vulnerability Description

A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP. The vulnerability is due to improper sanitization of user-supplied input in specific CLI commands. An attacker could exploit this vulnerability by accessing the CLI of an affected AP with administrator privileges and issuing crafted commands that result in directory traversal. A successful exploit could allow the attacker to view system files on the affected device, which could contain sensitive information. Software versions 8.8 and 8.9 are affected.

CVSS Score

4.4

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CiscoAironet Access Point Firmware8.8
CiscoAironet 1542D-
CiscoAironet 1542I-
CiscoAironet 1562D-
CiscoAironet 1562E-
CiscoAironet 1562I-
CiscoAironet 1800I-
CiscoAironet 1850E-
CiscoAironet 1850I-
CiscoAironet 2800E-
CiscoAironet 2800I-
CiscoAironet 3800E-
CiscoAironet 3800I-
CiscoAironet 3800P-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-1835?

CVE-2019-1835 is a vulnerability with a CVSS score of 4.4 (MEDIUM). A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP. The vulnerability is due to improper sanit...

How severe is CVE-2019-1835?

CVE-2019-1835 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-1835?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Aironet Access Point Firmware, Cisco Aironet 1542D, Cisco Aironet 1542I, Cisco Aironet 1562D, Cisco Aironet 1562E.