CVE-2023-20157
published 2023-05-18CVE-2023-20157: Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to…
PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.18%
64.1th percentile
Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_small_business_smart_and_managed_switches | — | — |
| cisco | small_business_series_switches | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered via improper validation of requests sent to the web-based user interface of Cisco Small Business Series Switches; monitor for anomalous or malformed HTTP requests to the switch web UI ↗
- →Attack is unauthenticated and remote — no credentials required; any external HTTP/HTTPS traffic to the management web UI from untrusted sources should be treated as suspicious ↗
- →Successful exploitation may result in root-level code execution or device crash (DoS); correlate unexpected reboots or process crashes on Cisco Small Business Series Switches with preceding web UI traffic ↗
- ·Vulnerability affects the web-based user interface of certain Cisco Small Business Series Switches; restrict management web UI access to trusted hosts/networks as a mitigation ↗
- ·Multiple CWEs are associated with this CVE (buffer overflow variants CWE-120, CWE-121, CWE-122, out-of-bounds write CWE-787, and information exposure CWE-200), indicating a broad attack surface within the web UI request handling code ↗
- ·Cisco Bug IDs CSCwe27386, CSCwe27393, and CSCwe27394 track the underlying defects; reference these when querying Cisco PSIRT or TAC for patch availability ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
vendor_cisco·2023-05-17·CVSS 9.8
CVE-2023-20024 [CRITICAL] CWE-120 Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-
Cisco
Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2023-20157 Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
CVE-2023-20157: Cisco Small Business Series Switches Buffer Overflow Vulnerabilities
Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-120, CWE-121, CWE-122, CWE-120, CWE-121, CWE-122, CWE-200, CWE-787, CWE-120, CWE-121, CWE-122, CWE-120, CWE-121, CWE-122, CWE-200, CWE-787
Bug IDs: CSCwe27386, CSCwe27393, CSCwe27394, CSCwe27386, CSCwe27393
GHSA
GHSA-486x-6qwp-2jh5: Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attack
ghsa_unreviewed·2023-05-18
CVE-2023-20157 [HIGH] CWE-120 GHSA-486x-6qwp-2jh5: Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attack
Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-18
Published