PT-2019-2196 · Cisco · Cisco Small Business Sx550+6

Publicado

2019-05-15

·

Atualizado

2020-10-16

·

CVE-2019-1806

CVSS v3.1

7.7

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches (affected versions not specified)
Description A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor could allow an authenticated, remote attacker to cause the SNMP application of an affected device to cease processing traffic, resulting in the CPU utilization reaching one hundred percent. This is due to improper validation of SNMP protocol data units (PDUs) in SNMP packets. An attacker could exploit this vulnerability by sending a malicious SNMP packet to an affected device, potentially causing the device to cease forwarding traffic and resulting in a denial of service (DoS) condition.
Recommendations For Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches, update to the latest firmware to address this vulnerability. As a temporary workaround, consider restricting access to the SNMP protocol to minimize the risk of exploitation.

Correção

Allocation of Resources Without Limits

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01966
CVE-2019-1806

Produtos afetados

Cisco Esw2 Series
Cisco Small Business Sx200
Cisco Small Business Sx250
Cisco Small Business Sx300
Cisco Small Business Sx350
Cisco Small Business Sx500
Cisco Small Business Sx550