HIGH · 7.5

CVE-2019-1892

A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a me...

Vulnerability Description

A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a memory corruption on an affected device. The vulnerability is due to improper validation of HTTPS packets. An attacker could exploit this vulnerability by sending a malformed HTTPS packet to the management web interface of the affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a denial of service (DoS) condition.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoSf200-24 Firmware< 1.4.10.6
CiscoSf200-24-
CiscoSf200-24P Firmware< 1.4.10.6
CiscoSf200-24P-
CiscoSf200-48 Firmware< 1.4.10.6
CiscoSf200-48-
CiscoSf200-48P Firmware< 1.4.10.6
CiscoSf200-48P-
CiscoSg200-18 Firmware< 1.4.10.6
CiscoSg200-18-
CiscoSg200-26 Firmware< 1.4.10.6
CiscoSg200-26-
CiscoSg200-26P Firmware< 1.4.10.6
CiscoSg200-26P-
CiscoSg200-50 Firmware< 1.4.10.6
CiscoSg200-50-
CiscoSg200-50P Firmware< 1.4.10.6
CiscoSg200-50P-
CiscoSg300-10 Firmware< 1.4.10.6
CiscoSg300-10-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-1892?

CVE-2019-1892 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a me...

How severe is CVE-2019-1892?

CVE-2019-1892 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-1892?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Sf200-24 Firmware, Cisco Sf200-24, Cisco Sf200-24P Firmware, Cisco Sf200-24P, Cisco Sf200-48 Firmware.