PT-2021-4812 · Cisco · Cisco Small Business 300 Series Managed Switches+2

Ken Pyle

·

Published

2021-11-03

·

Updated

2021-11-10

·

CVE-2021-40127

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Cisco Small Business 200 Series Smart Switches versions (affected versions not specified) Cisco Small Business 300 Series Managed Switches versions (affected versions not specified) Cisco Small Business 500 Series Stackable Managed Switches versions (affected versions not specified)
Description A vulnerability in the web-based management interface could allow an unauthenticated, remote attacker to render the interface unusable, resulting in a denial of service (DoS) condition. This issue is due to improper validation of HTTP requests. An attacker could exploit this by sending a crafted HTTP request to an affected device, potentially causing a permanent invalid redirect for requests sent to the interface, resulting in a DoS condition.
Recommendations For Cisco Small Business 200 Series Smart Switches, update to a version that fixes the improper validation of HTTP requests. For Cisco Small Business 300 Series Managed Switches, update to a version that fixes the improper validation of HTTP requests. For Cisco Small Business 500 Series Stackable Managed Switches, update to a version that fixes the improper validation of HTTP requests. As a temporary workaround, consider restricting access to the web-based management interface until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05540
CVE-2021-40127

Affected Products

Cisco Small Business 200 Series Smart Switches
Cisco Small Business 300 Series Managed Switches
Cisco Small Business 500 Series Stackable Managed Switches