VDB

CVE-2019-15260

CVE-2019-15260 PUBLISHED CVSS 9.800000190734863 CRITICAL

A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access control for certain URLs on an affected device. An attacker could exploit this vulnerability by requesting specific URLs from an affected AP. An exploit could allow the attacker to gain access to the device with elevated privileges. While the attacker would not be granted access to all possible configuration options, it could allow the attacker to view sensitive information and replace some options with values of their choosing, including wireless network configuration. It would also allow the attacker to disable the AP, creating a denial of service (DoS) condition for clients associated with the AP.

EPSS 7.10% · 91.7th percentile

Risk Scores

CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
7.10%
91.7th percentile

Affected Products

VendorProductVersions
ciscoaironet_1560_firmware8.5, 8.8
ciscoaironet_3800_firmware8.5, 8.8
ciscoaironet_1540_firmware8.8, 8.5
ciscoaironet_2800_firmware8.8, 8.5
ciscoaironet_1800_firmware8.8, 8.5
CiscoCisco Aironet Access Point Softwareunspecified
ciscoaironet_4800_firmware8.5, 8.8

Timeline

  • Oct 16, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›