Description
A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an unauthenticated, remote attacker to render the web-based management interface unusable, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause a permanent invalid redirect for requests sent to the web-based management interface of the device, resulting in a DoS condition.
Published: 2021-11-04
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-27314 A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an unauthenticated, remote attacker to render the web-based management interface unusable, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause a permanent invalid redirect for requests sent to the web-based management interface of the device, resulting in a DoS condition.
History

Thu, 07 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Sf200-24 Sf200-24 Firmware Sf200-24fp Sf200-24fp Firmware Sf200-24p Sf200-24p Firmware Sf200-48 Sf200-48 Firmware Sf200-48p Sf200-48p Firmware Sf200e-24 Sf200e-24 Firmware Sf200e-24p Sf200e-24p Firmware Sf200e-48 Sf200e-48 Firmware Sf200e-48p Sf200e-48p Firmware Sf300-08 Sf300-08 Firmware Sf300-24 Sf300-24 Firmware Sf300-24mp Sf300-24mp Firmware Sf300-24p Sf300-24p Firmware Sf300-24pp Sf300-24pp Firmware Sf300-48 Sf300-48 Firmware Sf300-48p Sf300-48p Firmware Sf300-48pp Sf300-48pp Firmware Sf302-08 Sf302-08 Firmware Sf302-08mp Sf302-08mp Firmware Sf302-08mpp Sf302-08mpp Firmware Sf302-08p Sf302-08p Firmware Sf302-08pp Sf302-08pp Firmware Sf500-24 Sf500-24 Firmware Sf500-24mp Sf500-24mp Firmware Sf500-24p Sf500-24p Firmware Sf500-48 Sf500-48 Firmware Sf500-48mp Sf500-48mp Firmware Sf500-48p Sf500-48p Firmware Sg200-08 Sg200-08 Firmware Sg200-08p Sg200-08p Firmware Sg200-10fp Sg200-10fp Firmware Sg200-18 Sg200-18 Firmware Sg200-26 Sg200-26 Firmware Sg200-26fp Sg200-26fp Firmware Sg200-26p Sg200-26p Firmware Sg200-50 Sg200-50 Firmware Sg200-50fp Sg200-50fp Firmware Sg200-50p Sg200-50p Firmware Sg300-10 Sg300-10 Firmware Sg300-10mp Sg300-10mp Firmware Sg300-10mpp Sg300-10mpp Firmware Sg300-10p Sg300-10p Firmware Sg300-10pp Sg300-10pp Firmware Sg300-20 Sg300-20 Firmware Sg300-28 Sg300-28 Firmware Sg300-28mp Sg300-28mp Firmware Sg300-28p Sg300-28p Firmware Sg300-28pp Sg300-28pp Firmware Sg300-28sfp Sg300-28sfp Firmware Sg300-52 Sg300-52 Firmware Sg300-52mp Sg300-52mp Firmware Sg300-52p Sg300-52p Firmware Sg300-sfp Sg300-sfp Firmware Sg500-28 Sg500-28 Firmware Sg500-28mpp Sg500-28mpp Firmware Sg500-28p Sg500-28p Firmware Sg500-52 Sg500-52 Firmware Sg500-52mp Sg500-52mp Firmware Sg500-52p Sg500-52p Firmware Sg500x-24 Sg500x-24 Firmware Sg500x-24mpp Sg500x-24mpp Firmware Sg500x-24p Sg500x-24p Firmware Sg500x-48 Sg500x-48 Firmware Sg500x-48mpp Sg500x-48mpp Firmware Sg500x-48p Sg500x-48p Firmware Sg500xg-8f8t Sg500xg-8f8t Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-07T21:45:08.555Z

Reserved: 2021-08-25T00:00:00.000Z

Link: CVE-2021-40127

cve-icon Vulnrichment

Updated: 2024-08-04T02:27:31.591Z

cve-icon NVD

Status : Modified

Published: 2021-11-04T16:15:09.643

Modified: 2024-11-21T06:23:38.027

Link: CVE-2021-40127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses