CVE-2019-1914
Summary
| CVE | CVE-2019-1914 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-07 06:15:00 UTC |
| Updated | 2019-10-01 23:15:00 UTC |
| Description | A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a malicious request to certain parts of the web management interface. To send the malicious request, the attacker needs a valid login session in the web management interface as a privilege level 15 user. Depending on the configuration of the affected switch, the malicious request must be sent via HTTP or HTTPS. A successful exploit could allow the attacker to execute arbitrary shell commands with the privileges of the root user. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Sf-220-24 | - | All | All | All |
| Hardware | Cisco | Sf-220-24 | - | All | All | All |
| Operating System | Cisco | Sf-220-24 Firmware | All | All | All | All |
| Operating System | Cisco | Sf-220-24 Firmware | All | All | All | All |
| Hardware | Cisco | Sf220-24p | - | All | All | All |
| Hardware | Cisco | Sf220-24p | - | All | All | All |
| Operating System | Cisco | Sf220-24p Firmware | All | All | All | All |
| Operating System | Cisco | Sf220-24p Firmware | All | All | All | All |
| Hardware | Cisco | Sf220-48 | - | All | All | All |
| Hardware | Cisco | Sf220-48 | - | All | All | All |
| Hardware | Cisco | Sf220-48p | - | All | All | All |
| Hardware | Cisco | Sf220-48p | - | All | All | All |
| Operating System | Cisco | Sf220-48p Firmware | All | All | All | All |
| Operating System | Cisco | Sf220-48p Firmware | All | All | All | All |
| Operating System | Cisco | Sf220-48 Firmware | All | All | All | All |
| Operating System | Cisco | Sf220-48 Firmware | All | All | All | All |
| Hardware | Cisco | Sg220-26 | - | All | All | All |
| Hardware | Cisco | Sg220-26 | - | All | All | All |
| Hardware | Cisco | Sg220-26p | - | All | All | All |
| Hardware | Cisco | Sg220-26p | - | All | All | All |
| Operating System | Cisco | Sg220-26p Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-26p Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-26 Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-26 Firmware | All | All | All | All |
| Hardware | Cisco | Sg220-28 | - | All | All | All |
| Hardware | Cisco | Sg220-28 | - | All | All | All |
| Hardware | Cisco | Sg220-28mp | - | All | All | All |
| Hardware | Cisco | Sg220-28mp | - | All | All | All |
| Operating System | Cisco | Sg220-28mp Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-28mp Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-28 Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-28 Firmware | All | All | All | All |
| Hardware | Cisco | Sg220-50 | - | All | All | All |
| Hardware | Cisco | Sg220-50 | - | All | All | All |
| Hardware | Cisco | Sg220-50p | - | All | All | All |
| Hardware | Cisco | Sg220-50p | - | All | All | All |
| Operating System | Cisco | Sg220-50p Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-50p Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-50 Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-50 Firmware | All | All | All | All |
| Hardware | Cisco | Sg220-52 | - | All | All | All |
| Hardware | Cisco | Sg220-52 | - | All | All | All |
| Operating System | Cisco | Sg220-52 Firmware | All | All | All | All |
| Operating System | Cisco | Sg220-52 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Realtek Managed Switch Controller (RTL83xx) Stack Overflow ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Cisco Small Business 220 Series Smart Switches Command Injection Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.