Vulnslist

find the latest Cisco vulnerabilities

Cisco Small Business 500 Series Switches Denial of Service Vulnerability

cisco-sa-20160128-sbs · Medium · Published · Updated

A vulnerability in the web-based GUI of the Cisco Small Business 500 Series Stackable Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160128-sbs

Workarounds

User must change the default password on the affected device. Alternatively, the user can upgrade to the first fixed firmware release.

CVEsCVE-2016-1303
Cisco Bug IDsCSCul65330
CVSS ScoreBase 5.4
Base 5.4 AV:N/AC:H/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C
Product Names From Source
Cisco Small Business 500 Series Stackable Managed Switches

Related Products

Product CVE Evidence