CVE-2019-1829 (CNNVD-201904-823)
中文标题:
多款Cisco产品操作系统命令注入漏洞
英文标题:
Cisco Aironet Series Access Points Command Injection Vulnerability
漏洞描述
中文描述:
Cisco Aironet 1540 Series APs等都是美国思科(Cisco)公司的产品。Cisco Aironet 1540 Series APs是一款1540系列访问接入点产品。Cisco Aironet 1560 Series APs是一款1560系列访问接入点产品。Cisco Aironet 1800 Series APs是一款1800系列访问接入点产品。 多款Cisco产品中的CLI存在配置错误漏洞,该漏洞源于网络系统或组件的使用过程中存在不合理的文件配置、参数配置等。以下产品受到影响:Cisco Aironet 1540 Series APs;Aironet 1560 Series APs;Aironet 1800 Series APs;Aironet 2800 Series APs;Aironet 3800 Series APs。
英文描述:
A vulnerability in the CLI of Cisco Aironet Series Access Points (APs) could allow an authenticated, local attacker to gain access to the underlying Linux operating system (OS) without the proper authentication. The attacker would need valid administrator device credentials. The vulnerability is due to improper validation of user-supplied input for certain CLI commands. An attacker could exploit this vulnerability by authenticating to an affected device and submitting crafted input for a CLI command. A successful exploit could allow the attacker to obtain access to the underlying Linux OS without proper authentication.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Aironet Access Point Software | 8.5(131.0) | - | - |
cpe:2.3:a:cisco:cisco_aironet_access_point_software:8.5(131.0):*:*:*:*:*:*:*
|
| cisco | aironet_access_point_firmware | * | - | - |
cpe:2.3:o:cisco:aironet_access_point_firmware:*:*:*:*:*:*:*:*
|
| cisco | aironet_access_point_firmware | 8.5\(131.0\) | - | - |
cpe:2.3:o:cisco:aironet_access_point_firmware:8.5\(131.0\):*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.0 (cna)
MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2019-1829 |
2025-11-11 15:20:08 | 2025-11-11 07:35:39 |
| NVD | nvd_CVE-2019-1829 |
2025-11-11 14:56:21 | 2025-11-11 07:44:10 |
| CNNVD | cnnvd_CNNVD-201904-823 |
2025-11-11 15:10:11 | 2025-11-11 07:54:29 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-201904-823
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']