CVE-2019-1920: Cisco Access Points

High severity, CVSS 7.4. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling condition for client authentication requests sent to a targeted interface configured for FT. An attacker could exploit this vulnerability by sending crafted authentication request traffic to the targeted interface, causing the device to restart unexpectedly.

Affected products

  • Cisco Access Points: before 8.2.170.0 (fixed in 8.2.170.0); from 8.3, before 8.3.150.0 (fixed in 8.3.150.0); from 8.4, before 8.5.131.0 (fixed in 8.5.131.0); from 8.6, before 8.8.100.0 (fixed in 8.8.100.0)
  • Cisco Aironet 3700e Firmware: version 15.3(3)jc14 only; version 15.3(3)jd6 only
  • Cisco Aironet 3700i Firmware: version 15.3(3)jc14 only; version 15.3(3)jd6 only
  • Cisco Aironet 3700p Firmware: version 15.3(3)jc14 only; version 15.3(3)jd6 only

Published 2019-07-17. Last modified 2026-06-17.