PT-2017-17272 · Cisco · Cisco Small Business Managed Switches

Published

2017-09-21

·

Updated

2020-09-04

·

CVE-2017-6720

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Small Business Managed Switches software (affected versions not specified)
Description A vulnerability in the Secure Shell (SSH) subsystem could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting in a denial of service (DoS) condition. The issue is due to improper processing of SSH connections. An attacker could exploit this by logging in to an affected switch via SSH and sending a malicious SSH message.
Recommendations For all affected versions, disable SSH until a fix is available to prevent exploitation. As a temporary workaround, consider restricting access to the SSH subsystem to minimize the risk of denial of service attacks.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6720

Affected Products

Cisco Small Business Managed Switches