Risk | High |
Patch available | YES |
Number of vulnerabilities | 9 |
CVE-ID | CVE-2023-20024 CVE-2023-20156 CVE-2023-20157 CVE-2023-20158 CVE-2023-20159 CVE-2023-20160 CVE-2023-20161 CVE-2023-20162 CVE-2023-20189 |
CWE-ID | CWE-122 CWE-20 CWE-121 CWE-119 CWE-200 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
Cisco Small Business 200 Series Smart Switches Hardware solutions / Routers & switches, VoIP, GSM, etc Cisco Small Business 300 Series Managed Switches Hardware solutions / Routers & switches, VoIP, GSM, etc Cisco Small Business 500 Series Stackable Managed Switches Hardware solutions / Routers & switches, VoIP, GSM, etc Cisco 250 Series Smart Switches Hardware solutions / Routers & switches, VoIP, GSM, etc Cisco 350 Series Managed Switches Hardware solutions / Routers & switches, VoIP, GSM, etc Cisco 350X Series Stackable Managed Switches Hardware solutions / Routers & switches, VoIP, GSM, etc Cisco 550X Series Stackable Managed Switches Hardware solutions / Routers & switches, VoIP, GSM, etc |
Vendor | Cisco Systems, Inc |
Security Bulletin
This security bulletin contains information about 9 vulnerabilities.
EUVDB-ID: #VU76262
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-20024
CWE-ID:
CWE-122 - Heap-based Buffer Overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing requests sent to the web interface. A remote non-authenticated attacker can send a specially crafted request to the web interface, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.
Install updates from vendor's website.
Vulnerable software versionsCisco Small Business 200 Series Smart Switches: All versions
Cisco Small Business 300 Series Managed Switches: All versions
Cisco Small Business 500 Series Stackable Managed Switches: All versions
Cisco 250 Series Smart Switches: before 2.5.9.16
Cisco 350 Series Managed Switches: before 2.5.9.16
Cisco 350X Series Stackable Managed Switches: before 2.5.9.16
Cisco 550X Series Stackable Managed Switches: before 2.5.9.16
External linkshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe27386
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe32312
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU76263
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-20156
CWE-ID:
CWE-122 - Heap-based Buffer Overflow
Exploit availability: No
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing requests sent to the web interface. A remote non-authenticated attacker can send a specially crafted request to the web interface, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.
Install updates from vendor's website.
Vulnerable software versionsCisco Small Business 200 Series Smart Switches: All versions
Cisco Small Business 300 Series Managed Switches: All versions
Cisco Small Business 500 Series Stackable Managed Switches: All versions
Cisco 250 Series Smart Switches: before 2.5.9.16
Cisco 350 Series Managed Switches: before 2.5.9.16
Cisco 350X Series Stackable Managed Switches: before 2.5.9.16
Cisco 550X Series Stackable Managed Switches: before 2.5.9.16
External linkshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe27393
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe32313
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU76264
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-20157
CWE-ID:
CWE-122 - Heap-based Buffer Overflow
Exploit availability: No
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing requests sent to the web interface. A remote non-authenticated attacker can send a specially crafted request to the web interface, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.
Install updates from vendor's website.
Vulnerable software versionsCisco Small Business 200 Series Smart Switches: All versions
Cisco Small Business 300 Series Managed Switches: All versions
Cisco Small Business 500 Series Stackable Managed Switches: All versions
Cisco 250 Series Smart Switches: before 2.5.9.16
Cisco 350 Series Managed Switches: before 2.5.9.16
Cisco 350X Series Stackable Managed Switches: before 2.5.9.16
Cisco 550X Series Stackable Managed Switches: before 2.5.9.16
External linkshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe27394
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe32315
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU76265
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-20158
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send specially crafted input to the web interface and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCisco Small Business 200 Series Smart Switches: All versions
Cisco Small Business 300 Series Managed Switches: All versions
Cisco Small Business 500 Series Stackable Managed Switches: All versions
Cisco 250 Series Smart Switches: before 2.5.9.16
Cisco 350 Series Managed Switches: before 2.5.9.16
Cisco 350X Series Stackable Managed Switches: before 2.5.9.16
Cisco 550X Series Stackable Managed Switches: before 2.5.9.16
External linkshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe27403
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe32318
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU76266
Risk: High
CVSSv3.1: 8.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-20159
CWE-ID:
CWE-121 - Stack-based buffer overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when handling requests. A remote unauthenticated attacker can send specially crafted input to the web interface, trigger a stack-based buffer overflow and execute arbitrary code with root privileges on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCisco Small Business 200 Series Smart Switches: All versions
Cisco Small Business 300 Series Managed Switches: All versions
Cisco Small Business 500 Series Stackable Managed Switches: All versions
Cisco 250 Series Smart Switches: before 2.5.9.16
Cisco 350 Series Managed Switches: before 2.5.9.16
Cisco 350X Series Stackable Managed Switches: before 2.5.9.16
Cisco 550X Series Stackable Managed Switches: before 2.5.9.16
External linkshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe27425
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe32323
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU76267
Risk: High
CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-20160
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when handling requests. A remote unauthenticated attacker can send specially crafted input to the web interface, trigger a based buffer overflow and execute arbitrary code with root privileges on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCisco Small Business 200 Series Smart Switches: All versions
Cisco Small Business 300 Series Managed Switches: All versions
Cisco Small Business 500 Series Stackable Managed Switches: All versions
Cisco 250 Series Smart Switches: before 2.5.9.16
Cisco 350 Series Managed Switches: before 2.5.9.16
Cisco 350X Series Stackable Managed Switches: before 2.5.9.16
Cisco 550X Series Stackable Managed Switches: before 2.5.9.16
External linkshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe27441
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe32326
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU76268
Risk: High
CVSSv3.1: 8.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-20161
CWE-ID:
CWE-121 - Stack-based buffer overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when handling requests. A remote unauthenticated attacker can send specially crafted input to the web interface, trigger a stack-based buffer overflow and execute arbitrary code with root privileges on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCisco Small Business 200 Series Smart Switches: All versions
Cisco Small Business 300 Series Managed Switches: All versions
Cisco Small Business 500 Series Stackable Managed Switches: All versions
Cisco 250 Series Smart Switches: before 2.5.9.16
Cisco 350 Series Managed Switches: before 2.5.9.16
Cisco 350X Series Stackable Managed Switches: before 2.5.9.16
Cisco 550X Series Stackable Managed Switches: before 2.5.9.16
External linkshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe27444
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe32334
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU76269
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-20162
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in the web interface. A remote attacker can read system configuration.
Install updates from vendor's website.
Vulnerable software versionsCisco Small Business 200 Series Smart Switches: All versions
Cisco Small Business 300 Series Managed Switches: All versions
Cisco Small Business 500 Series Stackable Managed Switches: All versions
Cisco 250 Series Smart Switches: before 2.5.9.16
Cisco 350 Series Managed Switches: before 2.5.9.16
Cisco 350X Series Stackable Managed Switches: before 2.5.9.16
Cisco 550X Series Stackable Managed Switches: before 2.5.9.16
External linkshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe32338
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe27445
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU76270
Risk: High
CVSSv3.1: 8.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-20189
CWE-ID:
CWE-121 - Stack-based buffer overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when handling requests. A remote unauthenticated attacker can send specially crafted input to the web interface, trigger a stack-based buffer overflow and execute arbitrary code with root privileges on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsCisco Small Business 200 Series Smart Switches: All versions
Cisco Small Business 300 Series Managed Switches: All versions
Cisco Small Business 500 Series Stackable Managed Switches: All versions
Cisco 250 Series Smart Switches: before 2.5.9.16
Cisco 350 Series Managed Switches: before 2.5.9.16
Cisco 350X Series Stackable Managed Switches: before 2.5.9.16
Cisco 550X Series Stackable Managed Switches: before 2.5.9.16
External linkshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe27424
http://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe32321
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.