← All CVEs

CVE-2019-15993

medium · 5.3

A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible from the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web UI of an affected device. A successful exploit could allow the attacker to access sensitive device information, which includes configuration files.

5.3
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2020-09-23
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-16CWE-287

Affected products

VendorProductAffected versions
ciscosg250x-24_firmware< 2.5.0.92
ciscosg250x-24all versions
ciscosg250x-24p_firmware< 2.5.0.92
ciscosg250x-24pall versions
ciscosg250x-48_firmware< 2.5.0.92
ciscosg250x-48all versions
ciscosg250x-48p_firmware< 2.5.0.92
ciscosg250x-48pall versions
ciscosg250-08_firmware< 2.5.0.92
ciscosg250-08all versions
ciscosg250-08hp_firmware< 2.5.0.92
ciscosg250-08hpall versions
ciscosg250-10p_firmware< 2.5.0.92
ciscosg250-10pall versions
ciscosg250-18_firmware< 2.5.0.92
ciscosg250-18all versions
ciscosg250-26_firmware< 2.5.0.92
ciscosg250-26all versions
ciscosg250-26hp_firmware< 2.5.0.92
ciscosg250-26hpall versions
ciscosg250-26p_firmware< 2.5.0.92
ciscosg250-26pall versions
ciscosg250-50_firmware< 2.5.0.92
ciscosg250-50all versions
ciscosg250-50hp_firmware< 2.5.0.92
ciscosg250-50hpall versions
ciscosg250-50p_firmware< 2.5.0.92
ciscosg250-50pall versions
ciscosf250-24_firmware< 2.5.0.92
ciscosf250-24all versions
ciscosf250-24p_firmware< 2.5.0.92
ciscosf250-24pall versions
ciscosf250-48_firmware< 2.5.0.92
ciscosf250-48all versions
ciscosf250-48hp_firmware< 2.5.0.92
ciscosf250-48hpall versions
ciscosg350-10_firmware< 2.5.0.92
ciscosg350-10all versions
ciscosg350-10p_firmware< 2.5.0.92
ciscosg350-10pall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-15993