CVE-2019-1814
Summary
| CVE | CVE-2019-1814 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-16 00:29:00 UTC |
| Updated | 2020-10-16 15:30:00 UTC |
| Description | A vulnerability in the interactions between the DHCP and TFTP features for Cisco Small Business 300 Series (Sx300) Managed Switches could allow an unauthenticated, remote attacker to cause the device to become low on system memory, which in turn could lead to an unexpected reload of the device and result in a denial of service (DoS) condition on an affected device. The vulnerability is due to a failure to free system memory when an unexpected DHCP request is received. An attacker could exploit this vulnerability by sending a crafted DHCP packet to the targeted device. A successful exploit could allow the attacker to cause an unexpected reload of the device. |
Risk And Classification
Problem Types: CWE-770
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Sf300-08 | - | All | All | All |
| Hardware | Cisco | Sf300-08 | - | All | All | All |
| Operating System | Cisco | Sf300-08 Firmware | All | All | All | All |
| Operating System | Cisco | Sf300-08 Firmware | All | All | All | All |
| Hardware | Cisco | Sf300-24 | - | All | All | All |
| Hardware | Cisco | Sf300-24 | - | All | All | All |
| Hardware | Cisco | Sf300-24mp | - | All | All | All |
| Hardware | Cisco | Sf300-24mp | - | All | All | All |
| Operating System | Cisco | Sf300-24mp Firmware | All | All | All | All |
| Operating System | Cisco | Sf300-24mp Firmware | All | All | All | All |
| Hardware | Cisco | Sf300-24p | - | All | All | All |
| Hardware | Cisco | Sf300-24p | - | All | All | All |
| Hardware | Cisco | Sf300-24pp | - | All | All | All |
| Hardware | Cisco | Sf300-24pp | - | All | All | All |
| Operating System | Cisco | Sf300-24pp Firmware | All | All | All | All |
| Operating System | Cisco | Sf300-24pp Firmware | All | All | All | All |
| Operating System | Cisco | Sf300-24p Firmware | All | All | All | All |
| Operating System | Cisco | Sf300-24p Firmware | All | All | All | All |
| Operating System | Cisco | Sf300-24 Firmware | All | All | All | All |
| Operating System | Cisco | Sf300-24 Firmware | All | All | All | All |
| Hardware | Cisco | Sf300-48 | - | All | All | All |
| Hardware | Cisco | Sf300-48 | - | All | All | All |
| Hardware | Cisco | Sf300-48p | - | All | All | All |
| Hardware | Cisco | Sf300-48p | - | All | All | All |
| Hardware | Cisco | Sf300-48pp | - | All | All | All |
| Hardware | Cisco | Sf300-48pp | - | All | All | All |
| Operating System | Cisco | Sf300-48pp Firmware | All | All | All | All |
| Operating System | Cisco | Sf300-48pp Firmware | All | All | All | All |
| Operating System | Cisco | Sf300-48p Firmware | All | All | All | All |
| Operating System | Cisco | Sf300-48p Firmware | All | All | All | All |
| Operating System | Cisco | Sf300-48 Firmware | All | All | All | All |
| Operating System | Cisco | Sf300-48 Firmware | All | All | All | All |
| Hardware | Cisco | Sf302-08 | - | All | All | All |
| Hardware | Cisco | Sf302-08 | - | All | All | All |
| Hardware | Cisco | Sf302-08mp | - | All | All | All |
| Hardware | Cisco | Sf302-08mp | - | All | All | All |
| Hardware | Cisco | Sf302-08mpp | - | All | All | All |
| Hardware | Cisco | Sf302-08mpp | - | All | All | All |
| Operating System | Cisco | Sf302-08mpp Firmware | All | All | All | All |
| Operating System | Cisco | Sf302-08mpp Firmware | All | All | All | All |
| Operating System | Cisco | Sf302-08mp Firmware | All | All | All | All |
| Operating System | Cisco | Sf302-08mp Firmware | All | All | All | All |
| Hardware | Cisco | Sf302-08p | - | All | All | All |
| Hardware | Cisco | Sf302-08p | - | All | All | All |
| Hardware | Cisco | Sf302-08pp | - | All | All | All |
| Hardware | Cisco | Sf302-08pp | - | All | All | All |
| Operating System | Cisco | Sf302-08pp Firmware | All | All | All | All |
| Operating System | Cisco | Sf302-08pp Firmware | All | All | All | All |
| Operating System | Cisco | Sf302-08p Firmware | All | All | All | All |
| Operating System | Cisco | Sf302-08p Firmware | All | All | All | All |
| Operating System | Cisco | Sf302-08 Firmware | All | All | All | All |
| Operating System | Cisco | Sf302-08 Firmware | All | All | All | All |
| Hardware | Cisco | Sg300-10 | - | All | All | All |
| Hardware | Cisco | Sg300-10 | - | All | All | All |
| Hardware | Cisco | Sg300-10mp | - | All | All | All |
| Hardware | Cisco | Sg300-10mp | - | All | All | All |
| Hardware | Cisco | Sg300-10mpp | - | All | All | All |
| Hardware | Cisco | Sg300-10mpp | - | All | All | All |
| Operating System | Cisco | Sg300-10mpp Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-10mpp Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-10mp Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-10mp Firmware | All | All | All | All |
| Hardware | Cisco | Sg300-10p | - | All | All | All |
| Hardware | Cisco | Sg300-10p | - | All | All | All |
| Hardware | Cisco | Sg300-10pp | - | All | All | All |
| Hardware | Cisco | Sg300-10pp | - | All | All | All |
| Operating System | Cisco | Sg300-10pp Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-10pp Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-10p Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-10p Firmware | All | All | All | All |
| Hardware | Cisco | Sg300-10sfp | - | All | All | All |
| Hardware | Cisco | Sg300-10sfp | - | All | All | All |
| Operating System | Cisco | Sg300-10sfp Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-10sfp Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-10 Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-10 Firmware | All | All | All | All |
| Hardware | Cisco | Sg300-20 | - | All | All | All |
| Hardware | Cisco | Sg300-20 | - | All | All | All |
| Operating System | Cisco | Sg300-20 Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-20 Firmware | All | All | All | All |
| Hardware | Cisco | Sg300-28 | - | All | All | All |
| Hardware | Cisco | Sg300-28 | - | All | All | All |
| Hardware | Cisco | Sg300-28mp | - | All | All | All |
| Hardware | Cisco | Sg300-28mp | - | All | All | All |
| Operating System | Cisco | Sg300-28mp Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-28mp Firmware | All | All | All | All |
| Hardware | Cisco | Sg300-28p | - | All | All | All |
| Hardware | Cisco | Sg300-28p | - | All | All | All |
| Hardware | Cisco | Sg300-28pp | - | All | All | All |
| Hardware | Cisco | Sg300-28pp | - | All | All | All |
| Operating System | Cisco | Sg300-28pp Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-28pp Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-28p Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-28p Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-28 Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-28 Firmware | All | All | All | All |
| Hardware | Cisco | Sg300-52 | - | All | All | All |
| Hardware | Cisco | Sg300-52 | - | All | All | All |
| Hardware | Cisco | Sg300-52mp | - | All | All | All |
| Hardware | Cisco | Sg300-52mp | - | All | All | All |
| Operating System | Cisco | Sg300-52mp Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-52mp Firmware | All | All | All | All |
| Hardware | Cisco | Sg300-52p | - | All | All | All |
| Hardware | Cisco | Sg300-52p | - | All | All | All |
| Operating System | Cisco | Sg300-52p Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-52p Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-52 Firmware | All | All | All | All |
| Operating System | Cisco | Sg300-52 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco Small Business 300 Series Managed Switches DHCP Denial of Service Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.