PT-2019-2196 · Cisco · Cisco Small Business Sx550+6

Published

2019-05-15

·

Updated

2020-10-16

·

CVE-2019-1806

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches (affected versions not specified)
Description A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor could allow an authenticated, remote attacker to cause the SNMP application of an affected device to cease processing traffic, resulting in the CPU utilization reaching one hundred percent. This is due to improper validation of SNMP protocol data units (PDUs) in SNMP packets. An attacker could exploit this vulnerability by sending a malicious SNMP packet to an affected device, potentially causing the device to cease forwarding traffic and resulting in a denial of service (DoS) condition.
Recommendations For Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches, update to the latest firmware to address this vulnerability. As a temporary workaround, consider restricting access to the SNMP protocol to minimize the risk of exploitation.

Fix

Allocation of Resources Without Limits

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01966
CVE-2019-1806

Affected Products

Cisco Esw2 Series
Cisco Small Business Sx200
Cisco Small Business Sx250
Cisco Small Business Sx300
Cisco Small Business Sx350
Cisco Small Business Sx500
Cisco Small Business Sx550