PT-2017-17272 · Cisco · Cisco Small Business Managed Switches
Published
2017-09-21
·
Updated
2020-09-04
·
CVE-2017-6720
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Small Business Managed Switches software (affected versions not specified)
Description
A vulnerability in the Secure Shell (SSH) subsystem could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting in a denial of service (DoS) condition. The issue is due to improper processing of SSH connections. An attacker could exploit this by logging in to an affected switch via SSH and sending a malicious SSH message.
Recommendations
For all affected versions, disable SSH until a fix is available to prevent exploitation. As a temporary workaround, consider restricting access to the SSH subsystem to minimize the risk of denial of service attacks.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Small Business Managed Switches