PT-2019-2793 · Cisco · Cisco Small Business 300 Series Switches+2

Published

2019-07-17

·

Updated

2019-10-09

·

CVE-2019-1943

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Small Business 200, 300, and 500 Series Switches software (affected versions not specified)
Description A vulnerability in the web interface could allow an unauthenticated, remote attacker to redirect a user to a malicious web page due to improper input validation of HTTP request parameters. This is known as an open redirect attack, often used in phishing attacks to trick users into visiting malicious sites. An attacker could exploit this by intercepting and modifying a user's HTTP request to cause the web interface to redirect the user to a specific malicious URL.
Recommendations For Cisco Small Business 200, 300, and 500 Series Switches software, consider restricting access to the web interface until a fix is available. As a temporary workaround, avoid using the web interface for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02745
CVE-2019-1943

Affected Products

Cisco Small Business 200 Series Switches
Cisco Small Business 300 Series Switches
Cisco Small Business 500 Series Switches