CVE-2019-15993
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.3%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible from the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web UI of an affected device. A successful exploit could allow the attacker to access sensitive device information, which includes configuration files.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 10.27% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16, CWE-287
- Affected
- cisco/sg250x-24 firmware · cisco/sg250x-24p firmware · cisco/sg250x-48 firmware · cisco/sg250x-48p firmware · cisco/sg250-08 firmware · cisco/sg250-08hp firmware · cisco/sg250-10p firmware · cisco/sg250-18 firmware · cisco/sg250-26 firmware · cisco/sg250-26hp firmware · cisco/sg250-26p firmware · cisco/sg250-50 firmware · cisco/sg250-50hp firmware · cisco/sg250-50p firmware · cisco/sf250-24 firmware · cisco/sf250-24p firmware · cisco/sf250-48 firmware · cisco/sf250-48hp firmware · cisco/sg350-10 firmware · cisco/sg350-10p firmware · +40 more
- Source
- psirt@cisco.com
References
- http://packetstormsecurity.com/files/171723/Cisco-Dell-Netgear-Information-Disclosure-Hash-Decrypter.html
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200129-smlbus-switch-disclosVendor Advisory
- http://packetstormsecurity.com/files/171723/Cisco-Dell-Netgear-Information-Disclosure-Hash-Decrypter.html
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200129-smlbus-switch-disclosVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.