Description
A vulnerability in the interactions between the DHCP and TFTP features for Cisco Small Business 300 Series (Sx300) Managed Switches could allow an unauthenticated, remote attacker to cause the device to become low on system memory, which in turn could lead to an unexpected reload of the device and result in a denial of service (DoS) condition on an affected device. The vulnerability is due to a failure to free system memory when an unexpected DHCP request is received. An attacker could exploit this vulnerability by sending a crafted DHCP packet to the targeted device. A successful exploit could allow the attacker to cause an unexpected reload of the device.
Published: 2019-05-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-10371 A vulnerability in the interactions between the DHCP and TFTP features for Cisco Small Business 300 Series (Sx300) Managed Switches could allow an unauthenticated, remote attacker to cause the device to become low on system memory, which in turn could lead to an unexpected reload of the device and result in a denial of service (DoS) condition on an affected device. The vulnerability is due to a failure to free system memory when an unexpected DHCP request is received. An attacker could exploit this vulnerability by sending a crafted DHCP packet to the targeted device. A successful exploit could allow the attacker to cause an unexpected reload of the device.
History

Thu, 21 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Sf300-08 Sf300-08 Firmware Sf300-24 Sf300-24 Firmware Sf300-24mp Sf300-24mp Firmware Sf300-24p Sf300-24p Firmware Sf300-24pp Sf300-24pp Firmware Sf300-48 Sf300-48 Firmware Sf300-48p Sf300-48p Firmware Sf300-48pp Sf300-48pp Firmware Sf302-08 Sf302-08 Firmware Sf302-08mp Sf302-08mp Firmware Sf302-08mpp Sf302-08mpp Firmware Sf302-08p Sf302-08p Firmware Sf302-08pp Sf302-08pp Firmware Sg300-10 Sg300-10 Firmware Sg300-10mp Sg300-10mp Firmware Sg300-10mpp Sg300-10mpp Firmware Sg300-10p Sg300-10p Firmware Sg300-10pp Sg300-10pp Firmware Sg300-10sfp Sg300-10sfp Firmware Sg300-20 Sg300-20 Firmware Sg300-28 Sg300-28 Firmware Sg300-28mp Sg300-28mp Firmware Sg300-28p Sg300-28p Firmware Sg300-28pp Sg300-28pp Firmware Sg300-52 Sg300-52 Firmware Sg300-52mp Sg300-52mp Firmware Sg300-52p Sg300-52p Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-21T19:25:40.906Z

Reserved: 2018-12-06T00:00:00.000Z

Link: CVE-2019-1814

cve-icon Vulnrichment

Updated: 2024-08-04T18:28:42.813Z

cve-icon NVD

Status : Modified

Published: 2019-05-16T00:29:00.260

Modified: 2024-11-21T04:37:26.363

Link: CVE-2019-1814

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses