QID 316847

Date Published: 2021-04-01

QID 316847: Cisco Small Business Smart and Managed Switches Denial of Service Vulnerability(cisco-sa-sbss-ipv6-dos-3bLk6vA)

A vulnerability in the IPv6 packet processing engine of Cisco Small Business Smart and Managed Switches
could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

Affected Products
The following Cisco products are affected if they have version prior to 2.5.5.47: 250 Series Smart Switches 350 Series Managed Switches 350X Series Stackable Managed Switches 550X Series Stackable Managed Switches Note: This is a potential check as the device model cannot be confirmed. Also this vulnerability is specific to IPv6 traffic. IPv4 traffic is not affected.

QID Detection Logic (Unauthenticated):
The unauthenticated check tries to fetch the Cisco Smart Switch vulnerable version in response to GET request to an API, but not the model number.

A successful exploit could allow the attacker to cause an unexpected reboot of the switch, leading to a DoS condition.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-sbss-ipv6-dos-3bLk6vA for more information.

    CVEs related to QID 316847

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-sbss-ipv6-dos-3bLk6vA URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbss-ipv6-dos-3bLk6vA