CVE-2019-1913
Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on the underlying operating system. The vulnerabilities are due to insufficient validation of user-supplied input and improper boundary checks when reading data into an internal buffer. An attacker could exploit these vulnerabilities by sending malicious requests to the web management interface of an affected device. Depending on the configuration of the affected switch, the malicious requests must be sent via HTTP or HTTPS.
EPSS 14.17% · 94.5th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Small Business 220 Series Smart Plus Switches | unspecified |
| cisco | sf220-48_firmware | 0 |
| cisco | sf220-24p_firmware | 0 |
| cisco | sg220-26_firmware | 0 |
| cisco | sf220-48p_firmware | 0 |
| cisco | sg220-52_firmware | 0 |
| cisco | sg220-28_firmware | 0 |
| cisco | sg220-26p_firmware | 0 |
| cisco | sg220-50_firmware | 0 |
| cisco | sg220-50p_firmware | 0 |
| cisco | sg220-28mp_firmware | 0 |
| cisco | sf-220-24_firmware | 0 |
Exploit Intelligence
- 20190806 Cisco Small Business 220 Series Smart Switches Remote Code Execution Vulnerabilities (circl)
- http://packetstormsecurity.com/files/154667/Realtek-Managed-Switch-Controller-RTL83xx-Stack-Overflow.html (circl)
- Cisco Small Business 220 Series - Multiple Vulnerabilities (variot)
- Cisco Small Business 220 Series - Multiple Vulnerabilities (variot)
- Cisco Small Business 220 Series - Multiple Vulnerabilities - Hardware remote Exploit (variot)
- Cisco Small Business 220 Series - Multiple Vulnerabilities - Hardware remote Exploit (variot)
- Cisco Small Business 220 Series - Multiple Vulnerabilities (variot)
- Cisco Small Business 220 Series - Multiple Vulnerabilities - Hardware remote Exploit (variot)
- Cisco Small Business 220 Series - Multiple Vulnerabilities (0day-today)
- Cisco Small Business 220 Series - Multiple Vulnerabilities (0day-today)
Timeline
- Oct 21, 2017 PoC Published
- Aug 6, 2019 CVE Published
- Sep 30, 2019 PoC Published
- Oct 1, 2019 PoC Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-rce advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190806-sb220-auth_bypass advisory
- http://packetstormsecurity.com/files/154667/Realtek-Managed-Switch-Controller-RTL83xx-Stack-Overflow.html url
- https://nvd.nist.gov/vuln/detail/CVE-2019-1913 advisory