← All CVEs

CVE-2019-1913

critical · 9.8

Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on the underlying operating system. The vulnerabilities are due to insufficient validation of user-supplied input and improper boundary checks when reading data into an internal buffer. An attacker could exploit these vulnerabilities by sending malicious requests to the web management interface of an affected device. Depending on the configuration of the affected switch, the malicious requests must be sent via HTTP or HTTPS.

9.8
CVSS
25.9%
EPSS (exploit prob.)
98th
EPSS percentile
2019-08-07
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
ciscosf-220-24_firmware< 1.1.4.4
ciscosf-220-24all versions
ciscosf220-24p_firmware< 1.1.4.4
ciscosf220-24pall versions
ciscosf220-48_firmware< 1.1.4.4
ciscosf220-48all versions
ciscosf220-48p_firmware< 1.1.4.4
ciscosf220-48pall versions
ciscosg220-26_firmware< 1.1.4.4
ciscosg220-26all versions
ciscosg220-26p_firmware< 1.1.4.4
ciscosg220-26pall versions
ciscosg220-28_firmware< 1.1.4.4
ciscosg220-28all versions
ciscosg220-28mp_firmware< 1.1.4.4
ciscosg220-28mpall versions
ciscosg220-50_firmware< 1.1.4.4
ciscosg220-50all versions
ciscosg220-50p_firmware< 1.1.4.4
ciscosg220-50pall versions
ciscosg220-52_firmware< 1.1.4.4
ciscosg220-52all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-1913