Cisco Small Business 220 Series Smart Switches Command Injection Vulnerability
Published Aug 7, 2019
7.2
HIGHCVSS 3.0
EPSS 24.85%
Description
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a malicious request to certain parts of the web management interface. To send the malicious request, the attacker needs a valid login session in the web management interface as a privilege level 15 user. Depending on the configuration of the affected switch, the malicious request must be sent via HTTP or HTTPS. A successful exploit could allow the attacker to execute arbitrary shell commands with the privileges of the root user.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<1.1.4.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Cisco | Cisco Small Business 220 Series Smart Plus Switches | n/a |
|
Configuration 1
- < 1.1.4.4
Configuration 2
- < 1.1.4.4
Configuration 3
- < 1.1.4.4
Configuration 4
- < 1.1.4.4
Configuration 5
- < 1.1.4.4
Configuration 6
- < 1.1.4.4
Configuration 7
- < 1.1.4.4
Configuration 8
- < 1.1.4.4
Running on/with
- n/a
Configuration 9
- < 1.1.4.4
Configuration 10
- < 1.1.4.4
Configuration 11
- < 1.1.4.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- http://packetstormsecurity.com/files/154667/Realtek-Managed-Switch-Controller-RTL83xx-Stack-Overflow.html x_refsource_MISC
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-inject vendor-advisoryx_refsource_CISCOVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/154667/Realtek-Managed-Switch-Controller-RTL83xx-Stack-Overflow.html | x_refsource_MISC | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-inject | vendor-advisoryx_refsource_CISCOVendor Advisory |
Change history (0)
No recorded changes yet.