Description
A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a memory corruption on an affected device. The vulnerability is due to improper validation of HTTPS packets. An attacker could exploit this vulnerability by sending a malformed HTTPS packet to the management web interface of the affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a denial of service (DoS) condition.
Published: 2019-07-06
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-10449 A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a memory corruption on an affected device. The vulnerability is due to improper validation of HTTPS packets. An attacker could exploit this vulnerability by sending a malformed HTTPS packet to the management web interface of the affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a denial of service (DoS) condition.
History

Tue, 19 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Esw2-350g52dc Esw2-350g52dc Firmware Esw2-550x48dc Esw2-550x48dc Firmware Sf200-24 Sf200-24 Firmware Sf200-24p Sf200-24p Firmware Sf200-48 Sf200-48 Firmware Sf200-48p Sf200-48p Firmware Sf300-08 Sf300-08 Firmware Sf300-24 Sf300-24 Firmware Sf300-24mp Sf300-24mp Firmware Sf300-24p Sf300-24p Firmware Sf300-24pp Sf300-24pp Firmware Sf300-48 Sf300-48 Firmware Sf300-48p Sf300-48p Firmware Sf300-48pp Sf300-48pp Firmware Sf302-08 Sf302-08 Firmware Sf302-08mp Sf302-08mp Firmware Sf302-08mpp Sf302-08mpp Firmware Sf302-08p Sf302-08p Firmware Sf302-08pp Sf302-08pp Firmware Sf500-24 Sf500-24 Firmware Sf500-24mp Sf500-24mp Firmware Sf500-24p Sf500-24p Firmware Sf500-48 Sf500-48 Firmware Sf500-48mp Sf500-48mp Firmware Sf500-48p Sf500-48p Firmware Sg200-18 Sg200-18 Firmware Sg200-26 Sg200-26 Firmware Sg200-26p Sg200-26p Firmware Sg200-50 Sg200-50 Firmware Sg200-50p Sg200-50p Firmware Sg300-10 Sg300-10 Firmware Sg300-10mp Sg300-10mp Firmware Sg300-10mpp Sg300-10mpp Firmware Sg300-10p Sg300-10p Firmware Sg300-10pp Sg300-10pp Firmware Sg300-10sfp Sg300-10sfp Firmware Sg300-20 Sg300-20 Firmware Sg300-28 Sg300-28 Firmware Sg300-28mp Sg300-28mp Firmware Sg300-28p Sg300-28p Firmware Sg300-28pp Sg300-28pp Firmware Sg300-28sfp Sg300-28sfp Firmware Sg300-52 Sg300-52 Firmware Sg300-52mp Sg300-52mp Firmware Sg300-52p Sg300-52p Firmware Sg500-28 Sg500-28 Firmware Sg500-28mpp Sg500-28mpp Firmware Sg500-28p Sg500-28p Firmware Sg500-52 Sg500-52 Firmware Sg500-52mp Sg500-52mp Firmware Sg500-52p Sg500-52p Firmware Sg500x-24 Sg500x-24 Firmware Sg500x-48 Sg500x-48 Firmware Sg500x-48mp Sg500x-48mp Firmware Sg500x-48p Sg500x-48p Firmware Sg500x24mpp Sg500x24mpp Firmware Sg500xg8f8t Sg500xg8f8t Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-19T19:03:39.713Z

Reserved: 2018-12-06T00:00:00.000Z

Link: CVE-2019-1892

cve-icon Vulnrichment

Updated: 2024-08-04T18:35:50.769Z

cve-icon NVD

Status : Modified

Published: 2019-07-06T02:15:11.293

Modified: 2024-11-21T04:37:37.757

Link: CVE-2019-1892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses