CVE-2017-6720
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting in a denial of service (DoS) condition. The vulnerability is due to improper processing of SSH connections. An attacker could exploit this vulnerability by logging in to an affected switch via SSH and sending a malicious SSH message. This vulnerability affects the following Cisco products when SSH is enabled: Small Business 300 Series Managed Switches, Small Business 500 Series Stackable Managed Switches, 350 Series Managed Switches, 350X Series Stackable Managed Switches, 550X Series Stackable Managed Switches, ESW2 Series Advanced Switches. Cisco Bug IDs: CSCvb48377.
Affected (85)
Products: Cisco: Sf302 08pp Firmware, Sf302 08mpp Firmware, Sg300 10pp Firmware, Sg300 10mpp Firmware, Sf300 24pp Firmware, Sf300 48pp Firmware, Sg300 28pp Firmware, Sf300 08 Firmware, Sf300 48p Firmware, Sg300 10mp Firmware, Sg300 10p Firmware, Sg300 10 Firmware, Sg300 28p Firmware, Sf300 24p Firmware, Sf302 08mp Firmware, Sg300 28 Firmware, Sf300 48 Firmware, Sg300 20 Firmware, Sf302 08p Firmware, Sg300 52 Firmware, Sf300 24 Firmware, Sf302 08 Firmware, Sf300 24mp Firmware, Sg300 10sfp Firmware, Sg300 28mp Firmware, Sg300 52p Firmware, Sg300 52mp Firmware, Sg500 28mpp Firmware, Sg500 52mp Firmware, Sg500xg 8f8t Firmware, Sf500 24 Firmware, Sf500 24p Firmware, Sf500 48 Firmware, Sf500 48p Firmware, Sg500 28 Firmware, Sg500 28p Firmware, Sg500 52 Firmware, Sg500 52p Firmware, Sg500x 24 Firmware, Sg500x 24p Firmware, Sg500x 48 Firmware, Sg500x 48p Firmware, Esw2 350g 52 Firmware, Esw2 350g 52dc Firmware, Esw2 550x 48 Firmware, Esw2 550x 48dc Firmware, Sg350 10 Firmware, Sg350 10p Firmware, Sg350 10mp Firmware, Sg355 10p Firmware, Sg350 28 Firmware, Sg350 28p Firmware, Sg350 28mp Firmware, Sf350 48 Firmware, Sf350 48p Firmware, Sf350 48mp Firmware, Sg350xg 2f10 Firmware, Sg350xg 24f Firmware, Sg350xg 24t Firmware, Sg350xg 48t Firmware, Sg350x 24 Firmware, Sg350x 24p Firmware, Sg350x 24mp Firmware, Sg350x 48 Firmware, Sg350x 48p Firmware, Sg350x 48mp Firmware, Sx550x 16ft Firmware, Sx550x 24ft Firmware, Sx550x 12f Firmware, Sx550x 24f Firmware, Sx550x 24 Firmware, Sx550x 52 Firmware, Sg550x 24 Firmware, Sg550x 24p Firmware, Sg550x 24mp Firmware, Sg550x 24mpp Firmware, Sg550x 48 Firmware, Sg550x 48p Firmware, Sg550x 48mp Firmware, Sf550x 24 Firmware, Sf550x 24p Firmware, Sf550x 24mp Firmware, Sf550x 48 Firmware, Sf550x 48p Firmware, Sf550x 48mp Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf302 08pp | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf302 08mpp | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 10pp | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 10mpp | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 24pp | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 48pp | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 28pp | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 08 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 48p | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 10mp | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 10p | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 10 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 28p | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 24p | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf302 08mp | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 28 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 48 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 20 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf302 08p | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 52 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 24 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf302 08 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 24mp | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 10sfp | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 28mp | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 52p | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 52mp | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500 28mpp | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500 52mp | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500xg 8f8t | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf500 24 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf500 24p | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf500 48 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf500 48p | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500 28 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500 28p | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500 52 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500 52p | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500x 24 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500x 24p | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500x 48 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500x 48p | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Esw2 350g 52 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Esw2 350g 52dc | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Esw2 550x 48 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.8.06 |
| Running on/with | Platform Versions |
|---|---|
Cisco Esw2 550x 48dc | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350 10 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350 10p | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350 10mp | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg355 10p | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350 28 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350 28p | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350 28mp | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf350 48 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf350 48p | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf350 48mp | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350xg 2f10 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350xg 24f | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350xg 24t | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350xg 48t | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350x 24 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350x 24p | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350x 24mp | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350x 48 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350x 48p | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg350x 48mp | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sx550x 16ft | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sx550x 24ft | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sx550x 12f | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sx550x 24f | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sx550x 24 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sx550x 52 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg550x 24 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg550x 24p | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg550x 24mp | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg550x 24mpp | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg550x 48 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg550x 48p | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg550x 48mp | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf550x 24 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf550x 24p | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf550x 24mp | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf550x 48 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf550x 48p | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3.0.130 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf550x 48mp | All versions |
References (4)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.