
Cisco has issued a warning about multiple vulnerabilities in Small Business Switches, which could allow an attacker to remotely access sensitive information on the devices and cause DoS.
Vulnerability CVE-2019-15993
This specific vulnerabilityis due to the lack of security with authentication elements for accessing the web UI.
An attacker could exploit the vulnerability to send a malicious HTTP to the malicious web UI and thus gain access to information about the device, such as configuration files.
Vulnerable products
The Cisco products affected by this vulnerability, if they are running firmware prior to version 2.5.0.92, are as follows:
250 Series Smart Switches
350 Series Managed Switches
350X Series Stackable Managed Switches
550X Series Stackable Managed Switches
Additionally, it affects the following Cisco products if they are running a software version prior to version 1.4.11.4:
200 Series Smart Switches
300 Series Managed Switches
500 Series Stackable Managed Switches
Cisco has released security updates to fix the vulnerability and confirmed that it is being exploited maliciously.
Vulnerability CVE-2020-3147 – DoS
The vulnerability is due to the lack of validation requests in the web UI. It allows a remote, unauthenticated attacker to perform a DoS attack on the affected device.
Vulnerable products
This vulnerability affects the following Cisco products if they are running firmware versions prior to version 1.3.7.18:
200 Series Smart Switches
300 Series Managed Switches
500 Series Stackable Managed Switches
Which products are not vulnerable?
Only products included in the list of "Vulnerable Products" released by Cisco are known to be affected by this vulnerability.
Cisco has confirmed that this vulnerability does not affect the following products:
250 Series Smart Switches
350 Series Managed Switches
350X Series Stackable Managed Switches
550X Series Stackable Managed Switches
Cisco released updates to fix the vulnerability and confirmed that there is no malicious use of the vulnerability.
