imPC@ndo IT

Tracker / CVE-2019-1914

CVE-2019-1914

High 7.2

A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a malicious request to certain parts of the web management interface. To send the malicious request, the attacker needs a valid login session in the web management interface as a privilege level 15 user. Depending on the configuration of the affected switch, the malicious request must be sent via HTTP or HTTPS. A successful exploit could allow the attacker to execute arbitrary shell commands with the privileges of the root user.

Affected products and versions

cisco sf-220-24_firmware · … → 1.1.4.4
cisco sf220-24p_firmware · … → 1.1.4.4
cisco sf220-48_firmware · … → 1.1.4.4
cisco sf220-48p_firmware · … → 1.1.4.4
cisco sg220-26_firmware · … → 1.1.4.4
cisco sg220-26p_firmware · … → 1.1.4.4
cisco sg220-28_firmware · … → 1.1.4.4
cisco sg220-28mp_firmware · … → 1.1.4.4
cisco sg220-50_firmware · … → 1.1.4.4
cisco sg220-50p_firmware · … → 1.1.4.4
cisco sg220-52_firmware · … → 1.1.4.4

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References