CVE编号
CVE-2019-1920利用情况
暂无补丁情况
N/A披露时间
2019-07-18漏洞描述
Cisco IOS接入点(AP)软件的802.11r快速转换(FT)实施中的漏洞可能允许未经身份验证的相邻攻击者在受影响的接口上导致拒绝服务(DoS)条件。该漏洞是由于发送到为FT配置的目标接口的客户端身份验证请求缺乏完整的错误处理条件。攻击者可以通过向目标接口发送精心设计的身份验证请求流量来利用此漏洞,从而导致设备意外重启。<br>解决建议
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190717-aironet-dos
参考链接 |
|
---|---|
http://www.securityfocus.com/bid/109312 | |
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-s... |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
系统 | amazon linux_2 | libonig | * |
Up to (excluding) 5.9.6-1.amzn2.0.3 |
|||||
运行在以下环境 | |||||||||
系统 | amazon_2 | oniguruma | * |
Up to (excluding) 5.9.6-1.amzn2.0.3 |
|||||
运行在以下环境 | |||||||||
系统 | centos_8 | oniguruma | * |
Up to (excluding) 7.3.20-1.module+el8.2.0+7373+b272fdef |
|||||
运行在以下环境 | |||||||||
系统 | cisco | access_points | * |
Up to (excluding) 8.2.170.0 |
|||||
运行在以下环境 | |||||||||
系统 | cisco | access_points | * |
From (including) 8.3 |
Up to (excluding) 8.3.150.0 |
||||
运行在以下环境 | |||||||||
系统 | cisco | access_points | * |
From (including) 8.4 |
Up to (excluding) 8.5.131.0 |
||||
运行在以下环境 | |||||||||
系统 | cisco | access_points | * |
From (including) 8.6 |
Up to (excluding) 8.8.100.0 |
||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_3700e_firmware | 15.3(3)jc14 | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_3700e_firmware | 15.3(3)jd6 | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_3700i_firmware | 15.3(3)jc14 | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_3700i_firmware | 15.3(3)jd6 | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_3700p_firmware | 15.3(3)jc14 | - | |||||
运行在以下环境 | |||||||||
系统 | cisco | aironet_3700p_firmware | 15.3(3)jd6 | - | |||||
运行在以下环境 | |||||||||
系统 | debian_10 | libonig | * |
Up to (excluding) 6.9.1-1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_8 | libonig | * |
Up to (excluding) 5.9.5-3.2+deb8u1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_9 | libonig | * |
Up to (excluding) 6.1.3-2+deb9u1 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_30 | libonig | * |
Up to (excluding) 6.9.2-4.fc30 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_31 | libonig | * |
Up to (excluding) 6.9.4-1.fc31 |
|||||
运行在以下环境 | |||||||||
系统 | oracle linux_8 | libonig | * |
Up to (excluding) 1.5.2-1.module+el8.2.0+5569+98c8b30d |
|||||
运行在以下环境 | |||||||||
系统 | oracle_8 | oniguruma | * |
Up to (excluding) 7.3.20-1.module+el8.2.0+7784+4033621d |
|||||
运行在以下环境 | |||||||||
系统 | redhat_8 | oniguruma | * |
Up to (excluding) 7.3.20-1.module+el8.2.0+7373+b272fdef |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_14.04_lts | libonig | * |
Up to (excluding) 5.9.1-1ubuntu1.1+esm2 |
|||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_3700e | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_3700i | - | - | |||||
运行在以下环境 | |||||||||
硬件 | cisco | aironet_3700p | - | - | |||||
- 攻击路径 相邻
- 攻击复杂度 低
- 权限要求 无
- 影响范围 已更改
- 用户交互 无
- 可用性 高
- 保密性 无
- 完整性 无
还没有评论,来说两句吧...