The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Computer vulnerabilities of Cisco Aironet

computer vulnerability bulletin CVE-2019-1675

Cisco Aironet Active Sensor: denial of service via Static Credentials Reboot

Synthesis of the vulnerability

An attacker can trigger a fatal error via Static Credentials Reboot of Cisco Aironet Active Sensor, in order to trigger a denial of service.
Impacted products: Cisco Aironet.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: intranet client.
Creation date: 08/02/2019.
Identifiers: cisco-sa-20190206-aas-creds, CSCvn36382, CVE-2019-1675, VIGILANCE-VUL-28468.

Description of the vulnerability

An attacker can trigger a fatal error via Static Credentials Reboot of Cisco Aironet Active Sensor, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability alert CVE-2018-0381

Cisco Aironet: denial of service via Aggregated Traffic Deadlock

Synthesis of the vulnerability

An attacker can generate a fatal error via Aggregated Traffic Deadlock of Cisco Aironet, in order to trigger a denial of service.
Impacted products: Cisco Aironet.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: user account.
Creation date: 18/10/2018.
Identifiers: CERTFR-2018-AVI-502, cisco-sa-20181017-aironet-dos, CSCvh21953, CVE-2018-0381, VIGILANCE-VUL-27556.

Description of the vulnerability

An attacker can generate a fatal error via Aggregated Traffic Deadlock of Cisco Aironet, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability note CVE-2018-5391

Linux kernel: denial of service via FragmentSmack

Synthesis of the vulnerability

An attacker can generate a fatal error via FragmentSmack of the Linux kernel, in order to trigger a denial of service.
Impacted products: GAiA, SecurePlatform, CheckPoint Security Gateway, Cisco Aironet, IOS XE Cisco, Nexus by Cisco, Prime Collaboration Assurance, Prime Infrastructure, Cisco Router, Secure ACS, Cisco CUCM, Cisco UCS, Cisco Unified CCX, Cisco IP Phone, Cisco Wireless Controller, Debian, BIG-IP Hardware, TMOS, Junos Space, Linux, Windows 10, Windows 2008 R0, Windows 2008 R2, Windows 2012, Windows 2016, Windows 7, Windows 8, Windows RT, openSUSE Leap, Palo Alto Firewall PA***, PAN-OS, RHEL, SUSE Linux Enterprise Desktop, SLES, Symantec Content Analysis, ProxySG by Symantec, Synology DSM, Ubuntu.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: internet client.
Creation date: 16/08/2018.
Identifiers: ADV180022, CERTFR-2018-AVI-390, CERTFR-2018-AVI-392, CERTFR-2018-AVI-419, CERTFR-2018-AVI-457, CERTFR-2018-AVI-478, CERTFR-2018-AVI-533, CERTFR-2019-AVI-233, cisco-sa-20180824-linux-ip-fragment, CVE-2018-5391, DLA-1466-1, DLA-1529-1, DSA-4272-1, FragmentSmack, JSA10917, K74374841, openSUSE-SU-2018:2404-1, openSUSE-SU-2018:2407-1, openSUSE-SU-2019:0274-1, PAN-SA-2018-0012, RHSA-2018:2785-01, RHSA-2018:2791-01, RHSA-2018:2846-01, RHSA-2018:2924-01, RHSA-2018:2925-01, RHSA-2018:2933-01, RHSA-2018:2948-01, RHSA-2018:3083-01, RHSA-2018:3096-01, RHSA-2018:3459-01, RHSA-2018:3540-01, RHSA-2018:3586-01, RHSA-2018:3590-01, sk134253, SUSE-SU-2018:2344-1, SUSE-SU-2018:2374-1, SUSE-SU-2018:2380-1, SUSE-SU-2018:2381-1, SUSE-SU-2018:2596-1, SUSE-SU-2019:0541-1, SUSE-SU-2019:1289-1, SYMSA1467, Synology-SA-18:44, USN-3740-1, USN-3740-2, USN-3741-1, USN-3741-2, USN-3741-3, USN-3742-1, USN-3742-2, USN-3742-3, VIGILANCE-VUL-27009, VU#641765.

Description of the vulnerability

An attacker can generate a fatal error via FragmentSmack of the Linux kernel, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

vulnerability announce CVE-2018-0234

Cisco Aironet: denial of service via PPTP

Synthesis of the vulnerability

An attacker can generate a fatal error via PPTP of Cisco Aironet, in order to trigger a denial of service.
Impacted products: Cisco Aironet.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: radio connection.
Creation date: 03/05/2018.
Identifiers: CERTFR-2018-AVI-211, cisco-sa-20180502-ap-ptp, CSCvf73890, CVE-2018-0234, VIGILANCE-VUL-26032.

Description of the vulnerability

An attacker can generate a fatal error via PPTP of Cisco Aironet, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

vulnerability alert CVE-2018-0250

Cisco Aironet: privilege escalation via CWA FlexConnect ACL

Synthesis of the vulnerability

An attacker can bypass restrictions via CWA FlexConnect ACL of Cisco Aironet, in order to escalate his privileges.
Impacted products: Cisco Aironet.
Severity: 2/4.
Consequences: privileged access/rights, data flow.
Provenance: radio connection.
Creation date: 03/05/2018.
Identifiers: CERTFR-2018-AVI-211, cisco-sa-20180502-ap-acl, CSCve17756, CVE-2018-0250, VIGILANCE-VUL-26031.

Description of the vulnerability

An attacker can bypass restrictions via CWA FlexConnect ACL of Cisco Aironet, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

vulnerability CVE-2018-0226

Cisco Aironet: privilege escalation via SSH

Synthesis of the vulnerability

An attacker can bypass restrictions via SSH of Cisco Aironet, in order to escalate his privileges.
Impacted products: Cisco Aironet.
Severity: 2/4.
Consequences: administrator access/rights, privileged access/rights.
Provenance: user account.
Creation date: 03/05/2018.
Identifiers: CERTFR-2018-AVI-211, cisco-sa-20180502-aironet-ssh, CSCva68116, CVE-2018-0226, VIGILANCE-VUL-26030.

Description of the vulnerability

An attacker can bypass restrictions via SSH of Cisco Aironet, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability note CVE-2018-0249

Cisco Aironet 1800: denial of service via 802.11 Association Requests

Synthesis of the vulnerability

An attacker can send malicious 802.11 Association Requests packets to Cisco Aironet 1800, in order to trigger a denial of service.
Impacted products: Cisco Aironet.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: radio connection.
Creation date: 03/05/2018.
Identifiers: CERTFR-2018-AVI-211, cisco-sa-20180502-aironet-dos, CSCvg02116, CVE-2018-0249, VIGILANCE-VUL-26029.

Description of the vulnerability

An attacker can send malicious 802.11 Association Requests packets to Cisco Aironet 1800, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability bulletin CVE-2018-0247

Cisco Aironet/WLC: privilege escalation via WebAuth

Synthesis of the vulnerability

An attacker can bypass restrictions via WebAuth of Cisco Aironet/WLC, in order to escalate his privileges.
Impacted products: Cisco Aironet, Cisco Wireless Controller.
Severity: 2/4.
Consequences: privileged access/rights, user access/rights.
Provenance: radio connection.
Creation date: 03/05/2018.
Identifiers: CERTFR-2018-AVI-211, cisco-sa-20180502-aironet-auth, CSCvc79502, CSCvf71789, CVE-2018-0247, VIGILANCE-VUL-26028.

Description of the vulnerability

An attacker can bypass restrictions via WebAuth of Cisco Aironet/WLC, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

vulnerability alert CVE-2017-12283

Cisco Aironet: denial of service via PAF

Synthesis of the vulnerability

An attacker can generate a fatal error via PAF of Cisco Aironet, in order to trigger a denial of service.
Impacted products: Cisco Aironet.
Severity: 2/4.
Consequences: denial of service on service, denial of service on client.
Provenance: radio connection.
Creation date: 02/11/2017.
Identifiers: CERTFR-2017-AVI-389, cisco-sa-20171101-aironet4, CSCvc20627, CVE-2017-12283, VIGILANCE-VUL-24291.

Description of the vulnerability

An attacker can generate a fatal error via PAF of Cisco Aironet, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

vulnerability CVE-2017-12281

Cisco Aironet: privilege escalation via MAC Authentication

Synthesis of the vulnerability

An attacker can bypass restrictions via MAC Authentication of Cisco Aironet, in order to escalate his privileges.
Impacted products: Cisco Aironet.
Severity: 2/4.
Consequences: user access/rights, data flow.
Provenance: radio connection.
Creation date: 02/11/2017.
Identifiers: CERTFR-2017-AVI-389, cisco-sa-20171101-aironet3, CSCvd46314, CVE-2017-12281, VIGILANCE-VUL-24290.

Description of the vulnerability

An attacker can bypass restrictions via MAC Authentication of Cisco Aironet, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)
Our database contains other pages. You can request a free trial to read them.

Display information about Cisco Aironet: