Open redirect in Cisco Systems, Inc products - CVE-2019-1943

 

Open redirect in Cisco Systems, Inc products - CVE-2019-1943

Published: July 22, 2019 / Updated: June 17, 2021


Vulnerability identifier: #VU19287
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1943
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to redirect a user to a malicious web page.

The vulnerability exists due to the improper input validation of the parameters of an HTTP request. A remote attacker can intercept a user's HTTP request and modify it into a request that causes the web interface to redirect the user to a specific malicious URL. 

Affected software

Cisco Small Business 500 Series Stackable Managed Switches
Cisco Small Business 300 Series Managed Switches
Cisco Small Business 200 Series Smart Switches

How to mitigate CVE-2019-1943

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins