Buffer overflow in Cisco Systems, Inc products - CVE-2019-1892

 

Buffer overflow in Cisco Systems, Inc products - CVE-2019-1892

Published: July 8, 2019


Vulnerability identifier: #VU19026
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1892
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a memory corruption on affected devices.

The vulnerability exists due to improper validation of HTTPS packets in the Secure Sockets Layer (SSL) input packet processor. A remote attacker can send a malformed HTTPS packet to the management web interface and cause an unexpected reload of the devices, resulting in a denial of service (DoS) condition.



Affected software

Cisco Small Business 500 Series Stackable Managed Switches
Cisco Small Business 300 Series Managed Switches
Cisco Small Business 200 Series Smart Switches

How to mitigate CVE-2019-1892

Install updates from vendor's website.

Cisco Small Business 500 Series Stackable Managed Switches - update to 1.4.10.6
Cisco Small Business 300 Series Managed Switches - update to 1.4.10.6
Cisco Small Business 200 Series Smart Switches - update to 1.4.10.6

External References

Related Security Bulletins