Vulnerability Details CVE-2019-1920
A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling condition for client authentication requests sent to a targeted interface configured for FT. An attacker could exploit this vulnerability by sending crafted authentication request traffic to the targeted interface, causing the device to restart unexpectedly.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.2%
CVSS Severity
CVSS v3 Score 7.4
CVSS v2 Score 6.1
Products affected by CVE-2019-1920
-
cpe:2.3:h:cisco:aironet_3700e:-
-
cpe:2.3:h:cisco:aironet_3700i:-
-
cpe:2.3:h:cisco:aironet_3700p:-
-
cpe:2.3:o:cisco:access_points:1.0
-
cpe:2.3:o:cisco:access_points:8.0
-
cpe:2.3:o:cisco:access_points:8.0(140.0)
-
cpe:2.3:o:cisco:access_points:8.1
-
cpe:2.3:o:cisco:access_points:8.2
-
cpe:2.3:o:cisco:access_points:8.2(141.0)
-
cpe:2.3:o:cisco:access_points:8.2(151.0)
-
cpe:2.3:o:cisco:access_points:8.3
-
cpe:2.3:o:cisco:access_points:8.3(102.0)
-
cpe:2.3:o:cisco:access_points:8.3(112.0)
-
cpe:2.3:o:cisco:access_points:8.3(114.74)
-
cpe:2.3:o:cisco:access_points:8.3.140.0
-
cpe:2.3:o:cisco:access_points:8.5
-
cpe:2.3:o:cisco:access_points:8.7
-
cpe:2.3:o:cisco:access_points:8.8
-
cpe:2.3:o:cisco:aironet_3700e_firmware:15.3(3)jc14
-
cpe:2.3:o:cisco:aironet_3700e_firmware:15.3(3)jd6
-
cpe:2.3:o:cisco:aironet_3700i_firmware:15.3(3)jc14
-
cpe:2.3:o:cisco:aironet_3700i_firmware:15.3(3)jd6
-
cpe:2.3:o:cisco:aironet_3700p_firmware:15.3(3)jc14
-
cpe:2.3:o:cisco:aironet_3700p_firmware:15.3(3)jd6