VDB
CVE-2019-15993
CVE-2019-15993
PUBLISHED
CVSS 7.5 HIGH
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible from the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web UI of an affected device. A successful exploit could allow the attacker to access sensitive device information, which includes configuration files.
EPSS 12.34% · 94.0th percentile
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
12.34%
94.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | sf250-24p_firmware | 0 |
| cisco | sg350-10mp_firmware | 0 |
| cisco | sf550x-24mp_firmware | 0 |
| cisco | sg350x-48mp_firmware | 0 |
| cisco | sg500x-24_firmware | 0 |
| cisco | sg250x-48p_firmware | 0 |
| cisco | sf300-48_firmware | 0 |
| cisco | sx550x-52_firmware | 0 |
| cisco | sg350-28mp_firmware | 0 |
| cisco | sg350x-24mp_firmware | 0 |
| cisco | sg300-10sfp_firmware | 0 |
| cisco | sf200-24p_firmware | 0, 0 |
| cisco | sg500-52p_firmware | 0 |
| cisco | sg350x-24p_firmware | 0 |
| cisco | sf550x-24p_firmware | 0 |
| cisco | sg250-26hp_firmware | 0 |
| cisco | sg250-10p_firmware | 0 |
| cisco | sg500-28_firmware | 0 |
| cisco | sg300-28pp_firmware | 0 |
| cisco | sf500-24_firmware | 0 |
…and 95 more
Exploit Intelligence
- 20200129 Cisco Small Business Switches Information Disclosure Vulnerability (circl)
- http://packetstormsecurity.com/files/171723/Cisco-Dell-Netgear-Information-Disclosure-Hash-Decrypter.html (circl)
- Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB - Information Disclosure (0day-today)
- Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB - Information Disclosure (0day-today)
Timeline
- Sep 23, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
References
- 20200129 Cisco Small Business Switches Information Disclosure Vulnerability vendor-advisory
- http://packetstormsecurity.com/files/171723/Cisco-Dell-Netgear-Information-Disclosure-Hash-Decrypter.html url
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smlbus-switch-dos-R6VquS2u advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-15993 advisory