Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2017-6720 |
CWE-ID | CWE-20 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
Cisco 550X Series Stackable Managed Switches Hardware solutions / Routers & switches, VoIP, GSM, etc Cisco 350X Series Stackable Managed Switches Hardware solutions / Routers & switches, VoIP, GSM, etc Cisco 350 Series Managed Switches Hardware solutions / Routers & switches, VoIP, GSM, etc Cisco ESW2 Series Advanced Switches Hardware solutions / Routers & switches, VoIP, GSM, etc Cisco Small Business 500 Series Stackable Managed Switches Hardware solutions / Routers & switches, VoIP, GSM, etc Cisco Small Business 300 Series Managed Switches Hardware solutions / Routers & switches, VoIP, GSM, etc |
Vendor | Cisco Systems, Inc |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU8561
Risk: Low
CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]
CVE-ID: CVE-2017-6720
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.
The weakness exists in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches due to improper processing of SSH connections. A remote attacker can log in to an affected switch via SSH and send a malicious SSH message to cause the switch to reload.
Successful exploitation of the vulnerability results in denial of service.
Update Cisco Small Business 300 Series Managed Switches, Cisco Small Business 500 Series Stackable Managed Switches and Cisco ESW2 Series Advanced Switches to version 1.4.8.06.
Update Cisco 350 Series Managed Switches, Cisco 350X Series Stackable Managed Switches and Cisco 550X Series Stackable Managed Switches to version 2.3.0.130.
Cisco 550X Series Stackable Managed Switches: All versions
Cisco 350X Series Stackable Managed Switches: All versions
Cisco 350 Series Managed Switches: All versions
Cisco ESW2 Series Advanced Switches: All versions
Cisco Small Business 500 Series Stackable Managed Switches: All versions
Cisco Small Business 300 Series Managed Switches: All versions
External linkshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170920-sbms
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.