Input validation error in Cisco Systems, Inc products - CVE-2020-3147
Published: January 30, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of requests sent to the web interface. A remote attacker can send a specially crafted request to the web interface and cause an unexpected reload of the device, resulting in a denial of service condition.
Affected software
Cisco Small Business 300 Series Managed Switches
Cisco Small Business 500 Series Stackable Managed Switches
How to mitigate CVE-2020-3147
Cisco Small Business 300 Series Managed Switches - update to 1.3.7.18
Cisco Small Business 500 Series Stackable Managed Switches - update to 1.3.7.18