Description
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches could allow an authenticated, remote attacker to cause the SNMP application of an affected device to cease processing traffic, resulting in the CPU utilization reaching one hundred percent. Manual intervention may be required before a device resumes normal operations. The vulnerability is due to improper validation of SNMP protocol data units (PDUs) in SNMP packets. An attacker could exploit this vulnerability by sending a malicious SNMP packet to an affected device. A successful exploit could allow the attacker to cause the device to cease forwarding traffic, which could result in a denial of service (DoS) condition. Cisco has released firmware updates that address this vulnerability.
Published: 2019-05-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-10363 A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches could allow an authenticated, remote attacker to cause the SNMP application of an affected device to cease processing traffic, resulting in the CPU utilization reaching one hundred percent. Manual intervention may be required before a device resumes normal operations. The vulnerability is due to improper validation of SNMP protocol data units (PDUs) in SNMP packets. An attacker could exploit this vulnerability by sending a malicious SNMP packet to an affected device. A successful exploit could allow the attacker to cause the device to cease forwarding traffic, which could result in a denial of service (DoS) condition. Cisco has released firmware updates that address this vulnerability.
History

Thu, 21 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Esw2-350g52dc Esw2-350g52dc Firmware Esw2-550x48dc Esw2-550x48dc Firmware Sf200-24 Sf200-24 Firmware Sf200-24p Sf200-24p Firmware Sf200-48 Sf200-48 Firmware Sf200-48p Sf200-48p Firmware Sf250-24 Sf250-24 Firmware Sf250-24p Sf250-24p Firmware Sf250-48 Sf250-48 Firmware Sf250-48hp Sf250-48hp Firmware Sf300-08 Sf300-08 Firmware Sf300-24 Sf300-24 Firmware Sf300-24mp Sf300-24mp Firmware Sf300-24p Sf300-24p Firmware Sf300-24pp Sf300-24pp Firmware Sf300-48 Sf300-48 Firmware Sf300-48p Sf300-48p Firmware Sf300-48pp Sf300-48pp Firmware Sf302-08 Sf302-08 Firmware Sf302-08mp Sf302-08mp Firmware Sf302-08mpp Sf302-08mpp Firmware Sf302-08p Sf302-08p Firmware Sf302-08pp Sf302-08pp Firmware Sf350-48 Sf350-48 Firmware Sf350-48mp Sf350-48mp Firmware Sf350-48p Sf350-48p Firmware Sf500-24 Sf500-24 Firmware Sf500-24mp Sf500-24mp Firmware Sf500-24p Sf500-24p Firmware Sf500-48 Sf500-48 Firmware Sf500-48mp Sf500-48mp Firmware Sf500-48p Sf500-48p Firmware Sf550x-24 Sf550x-24 Firmware Sf550x-24mp Sf550x-24mp Firmware Sf550x-24p Sf550x-24p Firmware Sf550x-48 Sf550x-48 Firmware Sf550x-48mp Sf550x-48mp Firmware Sf550x-48p Sf550x-48p Firmware Sg200-18 Sg200-18 Firmware Sg200-26 Sg200-26 Firmware Sg200-26p Sg200-26p Firmware Sg200-50 Sg200-50 Firmware Sg200-50p Sg200-50p Firmware Sg250-08 Sg250-08 Firmware Sg250-08hp Sg250-08hp Firmware Sg250-10p Sg250-10p Firmware Sg250-18 Sg250-18 Firmware Sg250-26 Sg250-26 Firmware Sg250-26hp Sg250-26hp Firmware Sg250-26p Sg250-26p Firmware Sg250-50 Sg250-50 Firmware Sg250-50hp Sg250-50hp Firmware Sg250-50p Sg250-50p Firmware Sg250x-24 Sg250x-24 Firmware Sg250x-24p Sg250x-24p Firmware Sg250x-48 Sg250x-48 Firmware Sg250x-48p Sg250x-48p Firmware Sg300-10 Sg300-10 Firmware Sg300-10mp Sg300-10mp Firmware Sg300-10mpp Sg300-10mpp Firmware Sg300-10p Sg300-10p Firmware Sg300-10pp Sg300-10pp Firmware Sg300-10sfp Sg300-10sfp Firmware Sg300-20 Sg300-20 Firmware Sg300-28 Sg300-28 Firmware Sg300-28mp Sg300-28mp Firmware Sg300-28p Sg300-28p Firmware Sg300-28pp Sg300-28pp Firmware Sg300-28sfp Sg300-28sfp Firmware Sg300-52 Sg300-52 Firmware Sg300-52mp Sg300-52mp Firmware Sg300-52p Sg300-52p Firmware Sg350-10 Sg350-10 Firmware Sg350-10mp Sg350-10mp Firmware Sg350-10p Sg350-10p Firmware Sg350-28 Sg350-28 Firmware Sg350-28mp Sg350-28mp Firmware Sg350-28p Sg350-28p Firmware Sg355-10p Sg355-10p Firmware Sg500-28 Sg500-28 Firmware Sg500-28mpp Sg500-28mpp Firmware Sg500-28p Sg500-28p Firmware Sg500-52 Sg500-52 Firmware Sg500-52mp Sg500-52mp Firmware Sg500-52p Sg500-52p Firmware Sg500x-24 Sg500x-24 Firmware Sg500x-24p Sg500x-24p Firmware Sg500x-48 Sg500x-48 Firmware Sg500x-48mp Sg500x-48mp Firmware Sg500x-48p Sg500x-48p Firmware Sg500x24mpp Sg500x24mpp Firmware Sg500xg8f8t Sg500xg8f8t Firmware Sg550x-24 Sg550x-24 Firmware Sg550x-24mp Sg550x-24mp Firmware Sg550x-24mpp Sg550x-24mpp Firmware Sg550x-24p Sg550x-24p Firmware Sg550x-48 Sg550x-48 Firmware Sg550x-48mp Sg550x-48mp Firmware Sg550x-48p Sg550x-48p Firmware Sx550x-12f Sx550x-12f Firmware Sx550x-16ft Sx550x-16ft Firmware Sx550x-24 Sx550x-24 Firmware Sx550x-24f Sx550x-24f Firmware Sx550x-24ft Sx550x-24ft Firmware Sx550x-52 Sx550x-52 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-21T19:26:01.587Z

Reserved: 2018-12-06T00:00:00.000Z

Link: CVE-2019-1806

cve-icon Vulnrichment

Updated: 2024-08-04T18:28:42.821Z

cve-icon NVD

Status : Modified

Published: 2019-05-15T22:29:00.247

Modified: 2024-11-21T04:37:25.137

Link: CVE-2019-1806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses