CVE-2016-1470
Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuz76230.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuz76230.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- cisco/small business 220 series smart plus switches
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-spsVendor Advisory
- http://www.securityfocus.com/bid/92709
- http://www.securitytracker.com/id/1036722
- http://www.synacktiv.com/ressources/advisories_cisco_switch_sg220_csrf.pdfExploit, Third Party Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-spsVendor Advisory
- http://www.securityfocus.com/bid/92709
- http://www.securitytracker.com/id/1036722
- http://www.synacktiv.com/ressources/advisories_cisco_switch_sg220_csrf.pdfExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.