Vulnslist

find the latest Cisco vulnerabilities

Cisco Small Business 220 Series Smart Plus Switches Web Interface Denial of Service Vulnerability

cisco-sa-20160831-sps2 · Medium · Published · Updated

A vulnerability in the web-based management interface of Cisco Small Business 220 Series Smart Plus (Sx220) Switches could allow an unauthenticated, remote attacker to cause the web-based management interface of an affected device to stop responding, resulting in a partial denial of service (DoS) condition on the device. The vulnerability is due to insufficient validation of HTTP requests by the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device via the interface. A successful exploit could allow the attacker to cause the interface to stop responding, resulting in a partial DoS condition that persists until the interface is restarted manually. Cisco has released firmware updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-sps2

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2016-1472
Cisco Bug IDsCSCuz76238
CVSS ScoreBase 5.0
Base 5.0 AV:N/AC:L/Au:N/C:N/I:N/A:P/E:F/RL:OF/RC:C
Product Names From Source
Cisco Small Business 220 Series Smart Plus Switches

Related Products

Product CVE Evidence
Cisco Small Business 220 Series Smart Switches CVE-2016-1472 Cisco OpenVuln
Cisco RV Series Routers CVE-2016-1472 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2016-1472 Cisco OpenVuln
Cisco Catalyst PON Series Switches CVE-2016-1472 Cisco OpenVuln
Cisco Business 220 Series Switches CVE-2016-1472 Cisco OpenVuln
Cisco Small Business 220 Series Smart Plus Switches CVE-2016-1472 Cisco OpenVuln