cisco-sa-20200226-wi-fi-info-disclosure
Vulnerability from csaf_cisco
Published
2020-02-27 00:00
Modified
2020-04-28 22:24
Summary
Wi-Fi Protected Network and Wi-Fi Protected Network 2 Information Disclosure Vulnerability

Notes

Summary
On February 26th, 2020, researchers Štefan Svorencík and Robert Lipovsky disclosed a vulnerability in the implementation of the wireless egress packet processing of certain Broadcom Wi-Fi chipsets. This vulnerability could allow an unauthenticated, adjacent attacker to decrypt Wi-Fi frames without the knowledge of the Wireless Protected Access (WPA) or Wireless Protected Access 2 (WPA2) Pairwise Temporal Key (PTK) used to secure the Wi-Fi network. The vulnerability exists because after an affected device handles a disassociation event it could send a limited number of Wi-Fi frames encrypted with a static, weak PTK. An attacker could exploit this vulnerability by acquiring these frames and decrypting them with the static PTK. A successful exploit could allow the attacker to decrypt Wi-Fi frames without the knowledge of the security session establishment used to secure the Wi-Fi network. Multiple Cisco wireless products are affected by this vulnerability. Cisco will release software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure ["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure"]
Affected Products
Cisco is investigating its product line to determine which products may be affected by this vulnerability. As the investigation progresses, Cisco will update this advisory with information about affected products, including the ID of the Cisco bug for each affected product. For information about whether a product is affected by this vulnerability, refer to the Vulnerable Products ["#vp"] and Products Confirmed Not Vulnerable ["#nv"] sections of this advisory. The Vulnerable Products section includes Cisco bug IDs for each affected product. The bugs are accessible through the Cisco Bug Search Tool and contain additional platform-specific information, including workarounds (if available) and fixed software releases.
Vulnerable Products
Product Cisco Bug ID Fixed Release Availability Routing and Switching - Enterprise and Service Provider Cisco Connected Grid Routers CSCvs87927 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87927"] Routing and Switching - Small Business Cisco RV160x and RV260x VPN Routers CSCvt23810 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt23810"] Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router CSCvs87875 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87875"] Cisco Small Business RV Series RV110W Wireless-N VPN Firewall CSCvs87870 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87870"] Cisco Small Business RV Series RV215W Wireless-N VPN Router CSCvs87874 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87874"] Cisco Small Business RV130 Series VPN Routers CSCvs87871 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87871"] Cisco WAP125 Wireless-AC Dual Band Desktop Access Point with PoE CSCvs87868 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87868"] Cisco WAP150 Wireless-AC/N Dual Radio Access Point with PoE CSCvs87877 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87877"] Cisco WAP361 Wireless-AC/N Dual Radio Wall Plate Access Point with PoE CSCvs87877 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87877"] Cisco WAP571 Wireless-AC/N Premium Dual Radio Access Point with PoE CSCvs93095 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs93095"] Cisco WAP571E Wireless-AC/N Premium Dual Radio Outdoor Access Point CSCvs93095 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs93095"] Voice and Unified Communications Devices Cisco IP Phone 8861 CSCvs87895 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87895"] Cisco Wireless IP Phone 8821 CSCvs87896 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87896"] Video, Streaming, TelePresence, and Transcoding Devices Cisco Webex Board (all models) CSCvs91690 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs91690"] Cisco Webex Desk Pro CSCvs91690 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs91690"] Cisco Webex Room Series CSCvs91690 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs91690"] Wireless Cisco Catalyst 9115 Series Wi-Fi 6 Access Points CSCvs87888 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87888"] Cisco Catalyst 9120 Series Access Points CSCvs87888 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87888"] Cisco Small Business 100 Series Wireless-N Access Points CSCvs87879 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87879"] Cisco Small Business 300 Series Wireless-N Access Points CSCvs87879 ["https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87879"] Cisco Meraki MR26 N/A Cisco Meraki MR32 N/A Cisco Meraki MR34 N/A Cisco Meraki MR72 N/A Security Cisco Meraki MX64W N/A Cisco Meraki MX65W N/A For additional information about the impact of this vulnerability on Cisco Meraki, see the Cisco Meraki Customer Advisories ["https://meraki.cisco.com/blog/cisco-meraki-customer-advisories/"]. Products Under Investigation Voice and Unified Communications Devices DX650 IP Phones - Running Android-based firmware
Products Confirmed Not Vulnerable
Only products listed in the Vulnerable Products ["#vp"] section of this advisory are known to be affected by this vulnerability. Endpoint Clients and Client Software Cisco AnyConnect Secure Mobility Client - Network Access Manager Routing and Switching - Enterprise and Service Provider Cisco 829 Industrial Integrated Services Routers Cisco c800 Series Integrated Services Routers Routing and Switching - Small Business Cisco RV132W ADSL2+ Wireless-N VPN Router Cisco RV134W VDSL2 Wireless-AC VPN Router Voice and Unified Communications Devices Cisco IP Phone 8800 Series with Multiplatform Firmware Cisco Unified IP Phone 8961 Cisco Unified IP Phone 9951 Cisco Unified IP Phone 9971 Cisco Unified Wireless IP Phone 7925 and 7926 Video, Streaming, TelePresence, and Transcoding Devices Cisco TelePresence MX Series Cisco TelePresence Profile Series Cisco TelePresence SX Series Cisco TelePresence System EX Series Cisco Telepresence Integrator C Series Cisco Vision Dynamic Signage Director - SV-4K digital media player Wireless Cisco Wireless LAN Controller Cisco Aironet 1560 Series Access Points Cisco Aironet 1810 Series OfficeExtend Access Points Cisco Aironet 1810w Series Access Points Cisco Aironet 1815 Series Access Points Cisco Aironet 1830 Series Access Points Cisco Aironet 1850 Series Access Points Cisco Aironet 2800 Series Access Points Cisco Aironet 3800 Series Access Points
Details
When a disassociation event is triggered, an affected device will delete the user-configured PTK as part of a sequence of cleanup operations. A number of Wi-Fi frames still buffered in the hardware egress queue could then be transmitted while encrypted with a static, weak PTK. There are two ways to acquire Wi-Fi frames encrypted with the static PTK: Triggering the disassociation event by injecting malicious packets into the wireless network and capturing the frames sent after the event. Passively listening to traffic from the wireless network and capturing the frames sent after a disassociation event. The frames affected by the weak encryption are the only ones present in the hardware egress buffer during the processing of a disassociation event. Further frames will not be accepted or queued. Under no circumstances can the attacker control the content or number of frames. This limits the information that can be obtained in case of successful exploitation of the vulnerability described in this advisory.
Workarounds
There are no workarounds that address this vulnerability.
Fixed Software
When considering software upgrades ["https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#fixes"], customers are advised to regularly consult the advisories for Cisco products, which are available from the Cisco Security Advisories and Alerts page ["https://www.cisco.com/go/psirt"], to determine exposure and a complete upgrade solution. In all cases, customers should ensure that the devices to be upgraded contain sufficient memory and confirm that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, customers are advised to contact the Cisco Technical Assistance Center (TAC) or their contracted maintenance providers. Fixed Releases See the Details section in the bug ID(s) in the Vulnerable Products ["#vp"] section for the most complete and current information.
Vulnerability Policy
To learn about Cisco security vulnerability disclosure policies and publications, see the Security Vulnerability Policy ["https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html"]. This document also contains instructions for obtaining fixed software and receiving security vulnerability information from Cisco.
Exploitation and Public Announcements
The vulnerability described in this advisory was discussed during the RSA conference of February 26, 2020. The Cisco Product Security Incident Response Team (PSIRT) is aware that proof-of-concept exploit code is available for the vulnerability that is described in this advisory. Cisco PSIRT is not aware of any malicious use of the vulnerability that is described in this advisory.
Source
Security researchers Štefan Svorencík and Robert Lipovsky of ESET have reported this vulnerability to the Industry Consortium for Advancement of Security on the Internet (ICASI). Cisco collaborated with ICASI during the investigation and disclosure of this vulnerability. More information can be found at http://www.icasi.org ["http://www.icasi.org/wi-fi-protected-access-wpa-vulnerabilities"]
Legal Disclaimer
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME. CISCO EXPECTS TO UPDATE THIS DOCUMENT AS NEW INFORMATION BECOMES AVAILABLE. A standalone copy or paraphrase of the text of this document that omits the distribution URL is an uncontrolled copy and may lack important information or contain factual errors. The information in this document is intended for end users of Cisco products.



{
  "document": {
    "acknowledgments": [
      {
        "summary": "Security researchers \u0160tefan Svorenc\u00edk and Robert Lipovsky of ESET have reported this vulnerability to the Industry Consortium for Advancement of Security on the Internet (ICASI).\r\n\r\nCisco collaborated with ICASI during the investigation and disclosure of this vulnerability. More information can be found at http://www.icasi.org [\"http://www.icasi.org/wi-fi-protected-access-wpa-vulnerabilities\"]"
      }
    ],
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "notes": [
      {
        "category": "summary",
        "text": "On February 26th, 2020, researchers \u0160tefan Svorenc\u00edk and Robert Lipovsky disclosed a vulnerability in the implementation of the wireless egress packet processing of certain Broadcom Wi-Fi chipsets. This vulnerability could allow an unauthenticated, adjacent attacker to decrypt Wi-Fi frames without the knowledge of the Wireless Protected Access (WPA) or Wireless Protected Access 2 (WPA2) Pairwise Temporal Key (PTK) used to secure the Wi-Fi network.\r\n\r\nThe vulnerability exists because after an affected device handles a disassociation event it could send a limited number of Wi-Fi frames encrypted with a static, weak PTK. An attacker could exploit this vulnerability by acquiring these frames and decrypting them with the static PTK. A successful exploit could allow the attacker to decrypt Wi-Fi frames without the knowledge of the security session establishment used to secure the Wi-Fi network.\r\n\r\n\r\nMultiple Cisco wireless products are affected by this vulnerability.\r\n\r\nCisco will release software updates that address this vulnerability. There are no workarounds that address this vulnerability.\r\n\r\nThis advisory is available at the following link:\r\nhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure [\"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure\"]",
        "title": "Summary"
      },
      {
        "category": "general",
        "text": "Cisco is investigating its product line to determine which products may be affected by this vulnerability. As the investigation progresses, Cisco will update this advisory with information about affected products, including the ID of the Cisco bug for each affected product.\r\n\r\nFor information about whether a product is affected by this vulnerability, refer to the Vulnerable Products [\"#vp\"] and Products Confirmed Not Vulnerable [\"#nv\"] sections of this advisory. The Vulnerable Products section includes Cisco bug IDs for each affected product. The bugs are accessible through the Cisco Bug Search Tool and contain additional platform-specific information, including workarounds (if available) and fixed software releases.",
        "title": "Affected Products"
      },
      {
        "category": "general",
        "text": "Product  Cisco Bug ID  Fixed Release Availability      Routing and Switching - Enterprise and Service Provider      Cisco Connected Grid Routers  CSCvs87927 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87927\"]         Routing and Switching - Small Business      Cisco RV160x and RV260x VPN Routers  CSCvt23810 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt23810\"]         Cisco RV340W Dual WAN Gigabit Wireless-AC VPN Router  CSCvs87875 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87875\"]         Cisco Small Business RV Series RV110W Wireless-N VPN Firewall  CSCvs87870 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87870\"]         Cisco Small Business RV Series RV215W Wireless-N VPN Router  CSCvs87874 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87874\"]         Cisco Small Business RV130 Series VPN Routers  CSCvs87871 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87871\"]         Cisco WAP125 Wireless-AC Dual Band Desktop Access Point with PoE  CSCvs87868 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87868\"]         Cisco WAP150 Wireless-AC/N Dual Radio Access Point with PoE  CSCvs87877 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87877\"]         Cisco WAP361 Wireless-AC/N Dual Radio Wall Plate Access Point with PoE  CSCvs87877 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87877\"]         Cisco WAP571 Wireless-AC/N Premium Dual Radio Access Point with PoE  CSCvs93095 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs93095\"]         Cisco WAP571E Wireless-AC/N Premium Dual Radio Outdoor Access Point  CSCvs93095 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs93095\"]         Voice and Unified Communications Devices      Cisco IP Phone 8861  CSCvs87895 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87895\"]         Cisco Wireless IP Phone 8821  CSCvs87896 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87896\"]         Video, Streaming, TelePresence, and Transcoding Devices      Cisco Webex Board (all models)  CSCvs91690 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs91690\"]         Cisco Webex Desk Pro  CSCvs91690 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs91690\"]         Cisco Webex Room Series  CSCvs91690 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs91690\"]         Wireless      Cisco Catalyst 9115 Series Wi-Fi 6 Access Points  CSCvs87888 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87888\"]         Cisco Catalyst 9120 Series Access Points  CSCvs87888 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87888\"]         Cisco Small Business 100 Series Wireless-N Access Points  CSCvs87879 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87879\"]         Cisco Small Business 300 Series Wireless-N Access Points  CSCvs87879 [\"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87879\"]         Cisco Meraki MR26    N/A         Cisco Meraki MR32   N/A         Cisco Meraki MR34   N/A         Cisco Meraki MR72   N/A         Security      Cisco Meraki MX64W   N/A         Cisco Meraki MX65W   N/A\r\nFor additional information about the impact of this vulnerability on Cisco Meraki, see the Cisco Meraki Customer Advisories [\"https://meraki.cisco.com/blog/cisco-meraki-customer-advisories/\"].\r\n  Products Under Investigation\r\nVoice and Unified Communications Devices\r\n\r\nDX650 IP Phones - Running Android-based firmware",
        "title": "Vulnerable Products"
      },
      {
        "category": "general",
        "text": "Only products listed in the Vulnerable Products [\"#vp\"] section of this advisory are known to be affected by this vulnerability.\r\n\r\nEndpoint Clients and Client Software\r\n\r\nCisco AnyConnect Secure Mobility Client - Network Access Manager\r\n\r\nRouting and Switching - Enterprise and Service Provider\r\n\r\nCisco 829 Industrial Integrated Services Routers\r\nCisco c800 Series Integrated Services Routers\r\n\r\nRouting and Switching - Small Business\r\n\r\nCisco RV132W ADSL2+ Wireless-N VPN Router\r\nCisco RV134W VDSL2 Wireless-AC VPN Router\r\n\r\nVoice and Unified Communications Devices\r\n\r\nCisco IP Phone 8800 Series with Multiplatform Firmware\r\nCisco Unified IP Phone 8961\r\nCisco Unified IP Phone 9951\r\nCisco Unified IP Phone 9971\r\nCisco Unified Wireless IP Phone 7925 and 7926\r\n\r\nVideo, Streaming, TelePresence, and Transcoding Devices\r\n\r\nCisco TelePresence MX Series\r\nCisco TelePresence Profile Series\r\nCisco TelePresence SX Series\r\nCisco TelePresence System EX Series\r\nCisco Telepresence Integrator C Series\r\nCisco Vision Dynamic Signage Director - SV-4K digital media player\r\n\r\nWireless\r\n\r\nCisco Wireless LAN Controller\r\nCisco Aironet 1560 Series Access Points\r\nCisco Aironet 1810 Series OfficeExtend Access Points\r\nCisco Aironet 1810w Series Access Points\r\nCisco Aironet 1815 Series Access Points\r\nCisco Aironet 1830 Series Access Points\r\nCisco Aironet 1850 Series Access Points\r\nCisco Aironet 2800 Series Access Points\r\nCisco Aironet 3800 Series Access Points",
        "title": "Products Confirmed Not Vulnerable"
      },
      {
        "category": "general",
        "text": "When a disassociation event is triggered, an affected device will delete the user-configured PTK as part of a sequence of cleanup operations. A number of Wi-Fi frames still buffered in the hardware egress queue could then be transmitted while encrypted with a static, weak PTK.\r\n\r\nThere are two ways to acquire Wi-Fi frames encrypted with the static PTK:\r\n\r\nTriggering the disassociation event by injecting malicious packets into the wireless network and capturing the frames sent after the event.\r\nPassively listening to traffic from the wireless network and capturing the frames sent after a disassociation event.\r\n\r\nThe frames affected by the weak encryption are the only ones present in the hardware egress buffer during the processing of a disassociation event. Further frames will not be accepted or queued. Under no circumstances can the attacker control the content or number of frames. This limits the information that can be obtained in case of successful exploitation of the vulnerability described in this advisory.",
        "title": "Details"
      },
      {
        "category": "general",
        "text": "There are no workarounds that address this vulnerability.",
        "title": "Workarounds"
      },
      {
        "category": "general",
        "text": "When considering software upgrades [\"https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#fixes\"], customers are advised to regularly consult the advisories for Cisco products, which are available from the Cisco Security Advisories and Alerts page [\"https://www.cisco.com/go/psirt\"], to determine exposure and a complete upgrade solution.\r\n\r\nIn all cases, customers should ensure that the devices to be upgraded contain sufficient memory and confirm that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, customers are advised to contact the Cisco Technical Assistance Center (TAC) or their contracted maintenance providers.\r\n      Fixed Releases\r\nSee the Details section in the bug ID(s) in the Vulnerable Products [\"#vp\"] section for the most complete and current information.",
        "title": "Fixed Software"
      },
      {
        "category": "general",
        "text": "To learn about Cisco security vulnerability disclosure policies and publications, see the Security Vulnerability Policy [\"https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html\"]. This document also contains instructions for obtaining fixed software and receiving security vulnerability information from Cisco.",
        "title": "Vulnerability Policy"
      },
      {
        "category": "general",
        "text": "The vulnerability described in this advisory was discussed during the RSA conference of February 26, 2020.\r\n\r\nThe Cisco Product Security Incident Response Team (PSIRT) is aware that proof-of-concept exploit code is available for the vulnerability that is described in this advisory.\r\n\r\nCisco PSIRT is not aware of any malicious use of the vulnerability that is described in this advisory.",
        "title": "Exploitation and Public Announcements"
      },
      {
        "category": "general",
        "text": "Security researchers \u0160tefan Svorenc\u00edk and Robert Lipovsky of ESET have reported this vulnerability to the Industry Consortium for Advancement of Security on the Internet (ICASI).\r\n\r\nCisco collaborated with ICASI during the investigation and disclosure of this vulnerability. More information can be found at http://www.icasi.org [\"http://www.icasi.org/wi-fi-protected-access-wpa-vulnerabilities\"]",
        "title": "Source"
      },
      {
        "category": "legal_disclaimer",
        "text": "THIS DOCUMENT IS PROVIDED ON AN \"AS IS\" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME. CISCO EXPECTS TO UPDATE THIS DOCUMENT AS NEW INFORMATION BECOMES AVAILABLE.\r\n\r\nA standalone copy or paraphrase of the text of this document that omits the distribution URL is an uncontrolled copy and may lack important information or contain factual errors. The information in this document is intended for end users of Cisco products.",
        "title": "Legal Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "Emergency Support:\r\n+1 877 228 7302 (toll-free within North America)\r\n+1 408 525 6532 (International direct-dial)\r\nNon-emergency Support:\r\nEmail: psirt@cisco.com\r\nSupport requests that are received via e-mail are typically acknowledged within 48 hours.",
      "issuing_authority": "Cisco product security incident response is the responsibility of the Cisco Product Security Incident Response Team (PSIRT). The Cisco PSIRT is a dedicated, global team that manages the receipt, investigation, and public reporting of security vulnerability information that is related to Cisco products and networks. The on-call Cisco PSIRT works 24x7 with Cisco customers, independent security researchers, consultants, industry organizations, and other vendors to identify possible security issues with Cisco products and networks.\r\nMore information can be found in Cisco Security Vulnerability Policy available at https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html",
      "name": "Cisco",
      "namespace": "https://wwww.cisco.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Wi-Fi Protected Network and Wi-Fi Protected Network 2 Information Disclosure Vulnerability",
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure"
      },
      {
        "category": "external",
        "summary": "Cisco Security Vulnerability Policy",
        "url": "https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html"
      },
      {
        "category": "external",
        "summary": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure",
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200226-wi-fi-info-disclosure"
      },
      {
        "category": "external",
        "summary": "CSCvs87927",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87927"
      },
      {
        "category": "external",
        "summary": "CSCvt23810",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt23810"
      },
      {
        "category": "external",
        "summary": "CSCvs87875",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87875"
      },
      {
        "category": "external",
        "summary": "CSCvs87870",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87870"
      },
      {
        "category": "external",
        "summary": "CSCvs87874",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87874"
      },
      {
        "category": "external",
        "summary": "CSCvs87871",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87871"
      },
      {
        "category": "external",
        "summary": "CSCvs87868",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87868"
      },
      {
        "category": "external",
        "summary": "CSCvs87877",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87877"
      },
      {
        "category": "external",
        "summary": "CSCvs87877",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87877"
      },
      {
        "category": "external",
        "summary": "CSCvs93095",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs93095"
      },
      {
        "category": "external",
        "summary": "CSCvs93095",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs93095"
      },
      {
        "category": "external",
        "summary": "CSCvs87895",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87895"
      },
      {
        "category": "external",
        "summary": "CSCvs87896",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87896"
      },
      {
        "category": "external",
        "summary": "CSCvs91690",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs91690"
      },
      {
        "category": "external",
        "summary": "CSCvs91690",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs91690"
      },
      {
        "category": "external",
        "summary": "CSCvs91690",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs91690"
      },
      {
        "category": "external",
        "summary": "CSCvs87888",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87888"
      },
      {
        "category": "external",
        "summary": "CSCvs87888",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87888"
      },
      {
        "category": "external",
        "summary": "CSCvs87879",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87879"
      },
      {
        "category": "external",
        "summary": "CSCvs87879",
        "url": "https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87879"
      },
      {
        "category": "external",
        "summary": "Cisco Meraki Customer Advisories",
        "url": "https://meraki.cisco.com/blog/cisco-meraki-customer-advisories/"
      },
      {
        "category": "external",
        "summary": "considering software upgrades",
        "url": "https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#fixes"
      },
      {
        "category": "external",
        "summary": "Cisco Security Advisories and Alerts page",
        "url": "https://www.cisco.com/go/psirt"
      },
      {
        "category": "external",
        "summary": "Security Vulnerability Policy",
        "url": "https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html"
      },
      {
        "category": "external",
        "summary": "http://www.icasi.org",
        "url": "http://www.icasi.org/wi-fi-protected-access-wpa-vulnerabilities"
      }
    ],
    "title": "Wi-Fi Protected Network and Wi-Fi Protected Network 2 Information Disclosure Vulnerability",
    "tracking": {
      "current_release_date": "2020-04-28T22:24:15+00:00",
      "generator": {
        "date": "2022-09-03T03:42:35+00:00",
        "engine": {
          "name": "TVCE"
        }
      },
      "id": "cisco-sa-20200226-wi-fi-info-disclosure",
      "initial_release_date": "2020-02-27T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2020-02-26T22:38:13+00:00",
          "number": "1.0.0",
          "summary": "Initial public release."
        },
        {
          "date": "2020-03-25T20:58:26+00:00",
          "number": "1.1.0",
          "summary": "Updated Vulnerable Products, Products Confirmed Not Vulnerable, and included information about publicly available code to exploit this vulnerability."
        },
        {
          "date": "2020-04-28T22:24:15+00:00",
          "number": "1.2.0",
          "summary": "Updated Vulnerable Products, and included information about the impact of this vulnerability on Cisco Meraki products."
        }
      ],
      "status": "interim",
      "version": "1.2.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "category": "product_family",
            "name": "Cisco IP phone",
            "product": {
              "name": "Cisco IP phone ",
              "product_id": "CSAFPID-4473"
            }
          }
        ],
        "category": "vendor",
        "name": "Cisco"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2019-15126",
      "notes": [
        {
          "category": "other",
          "text": "Complete.",
          "title": "Affected Product Comprehensiveness"
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-4473"
        ]
      },
      "release_date": "2020-02-27T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Cisco has released software updates that address this vulnerability.",
          "product_ids": [
            "CSAFPID-4473"
          ],
          "url": "https://software.cisco.com"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.0"
          },
          "products": [
            "CSAFPID-4473"
          ]
        }
      ],
      "title": "kr00k-Information Discosure Vulnerability"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…