PT-2021-4812 · Cisco · Cisco Small Business 300 Series Managed Switches+2
Ken Pyle
·
Published
2021-11-03
·
Updated
2021-11-10
·
CVE-2021-40127
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Cisco Small Business 200 Series Smart Switches versions (affected versions not specified)
Cisco Small Business 300 Series Managed Switches versions (affected versions not specified)
Cisco Small Business 500 Series Stackable Managed Switches versions (affected versions not specified)
Description
A vulnerability in the web-based management interface could allow an unauthenticated, remote attacker to render the interface unusable, resulting in a denial of service (DoS) condition. This issue is due to improper validation of HTTP requests. An attacker could exploit this by sending a crafted HTTP request to an affected device, potentially causing a permanent invalid redirect for requests sent to the interface, resulting in a DoS condition.
Recommendations
For Cisco Small Business 200 Series Smart Switches, update to a version that fixes the improper validation of HTTP requests.
For Cisco Small Business 300 Series Managed Switches, update to a version that fixes the improper validation of HTTP requests.
For Cisco Small Business 500 Series Stackable Managed Switches, update to a version that fixes the improper validation of HTTP requests.
As a temporary workaround, consider restricting access to the web-based management interface until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Small Business 200 Series Smart Switches
Cisco Small Business 300 Series Managed Switches
Cisco Small Business 500 Series Stackable Managed Switches