CVE-2019-18991 - CVE House
Back to Database
Status published Medium CVE-2019-18991

A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8),...

Vulnerability Description

A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-18991

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

atheros ar9132 firmware, atheros ar9283 firmware, atheros ar9285 firmware
Vulnerable Versions:
3.60\(amx.8\), 1.85, 1.0.0.12na

Timeline

Official Publish: September 30th, 2020
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AC:L/AV:A/A:N/C:L/I:L/PR:N/S:C/UI:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.