cbcvebase.
CVE-2023-20189
published 2023-05-18

CVE-2023-20189: Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to…

PriorityP275critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
11.10%
95.4th percentile
Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscocisco_small_business_smart_and_managed_switches
ciscosmall_business_series_switches

Detection & IOCsextracted from sources · hover to see the quote

  • Target attack surface is the web-based user interface of Cisco Small Business Series Switches; monitor for anomalous or malformed HTTP requests sent to the web interface of these devices
  • Exploitation requires no authentication; alert on unauthenticated remote connections to the management web UI of Cisco Small Business Series Switches
  • Vulnerability classes include stack-based and heap-based buffer overflows (CWE-121, CWE-122) as well as out-of-bounds writes (CWE-787); look for oversized payloads or unexpected data lengths in HTTP request bodies/headers targeting the switch web UI
  • ·Multiple Cisco Bug IDs are associated with this CVE group; patch tracking should reference all listed IDs: CSCwe27386, CSCwe27393, CSCwe27394
  • ·This CVE is part of a broader advisory (cisco-sa-sg-web-multi-S9g4Nkgv) covering multiple buffer overflow vulnerabilities across Cisco Small Business Series Switches; remediation and detection scope should cover all CVEs in the advisory, not just CVE-2023-20189

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.