CVE-2019-1913
Summary
| CVE | CVE-2019-1913 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-07 06:15:00 UTC |
| Updated | 2019-10-01 23:15:00 UTC |
| Description | Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on the underlying operating system. The vulnerabilities are due to insufficient validation of user-supplied input and improper boundary checks when reading data into an internal buffer. An attacker could exploit these vulnerabilities by sending malicious requests to the web management interface of an affected device. Depending on the configuration of the affected switch, the malicious requests must be sent via HTTP or HTTPS. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Sf-220-24 | - | All | All | All |
| Hardware | Cisco | Sf-220-24 | - | All | All | All |
| Operating System | Cisco | Sf-220-24 Firmware | All | All | All | All |
| Operating System | Cisco | Sf-220-24 Firmware | All | All | All | All |
| Hardware | Cisco | Sf220-24p | - | All | All | All |
| Hardware | Cisco | Sf220-24p | - | All | All | All |
| Operating System | Cisco | Sf220-24p Firmware | All | All | All | All |
| Operating System | Cisco | Sf220-24p Firmware | All | All | All | All |
| Hardware | Cisco | Sf220-48 | - | All | All | All |
| Hardware | Cisco | Sf220-48 | - | All | All | All |
| Hardware | Cisco | Sf220-48p | - | All | All | All |
| Hardware | Cisco | Sf220-48p | - | All | All | All |
| Operating System | Cisco | Sf220-48p Firmware | All | All | All | All |
| Operating System | Cisco | Sf220-48p Firmware | All | All | All | All |
| Operating System | Cisco | Sf220-48 Firmware | All | All | All | All |
| Operating System | Cisco | Sf220-48 Firmware | All | All | All | All |
| Hardware | Cisco | Sg220-26 | - | All | All | All |
| Hardware | Cisco | Sg220-26 | - | All | All | All |
| Hardware | Cisco | Sg220-26p | - | All | All | All |
| Hardware | Cisco | Sg220-26p | - | All | All | All |
| Operating System | Cisco | Sg220-26p Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-26p Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-26 Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-26 Firmware | All | All | All | All |
| Hardware | Cisco | Sg220-28 | - | All | All | All |
| Hardware | Cisco | Sg220-28 | - | All | All | All |
| Hardware | Cisco | Sg220-28mp | - | All | All | All |
| Hardware | Cisco | Sg220-28mp | - | All | All | All |
| Operating System | Cisco | Sg220-28mp Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-28mp Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-28 Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-28 Firmware | All | All | All | All |
| Hardware | Cisco | Sg220-50 | - | All | All | All |
| Hardware | Cisco | Sg220-50 | - | All | All | All |
| Hardware | Cisco | Sg220-50p | - | All | All | All |
| Hardware | Cisco | Sg220-50p | - | All | All | All |
| Operating System | Cisco | Sg220-50p Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-50p Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-50 Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-50 Firmware | All | All | All | All |
| Hardware | Cisco | Sg220-52 | - | All | All | All |
| Hardware | Cisco | Sg220-52 | - | All | All | All |
| Operating System | Cisco | Sg220-52 Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-52 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Small Business 220 Series Smart Switches Remote Code Execution Vulnerabilities | CISCO | tools.cisco.com | Vendor Advisory |
| Realtek Managed Switch Controller (RTL83xx) Stack Overflow ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.