← Back

CVE-2019-1943

Published: Jul 17, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting a user's HTTP request and modifying it into a request that causes the web interface to redirect the user to a specific malicious URL. This type of vulnerability is known as an open redirect attack and is used in phishing attacks that get users to unknowingly visit malicious sites.

Affected (57)

Products: Cisco: Sg200 50 Firmware, Sg200 50p Firmware, Sg200 50fp Firmware, Sg200 26 Firmware, Sg200 26p Firmware, Sg200 26fp Firmware, Sg200 18 Firmware, Sg200 10fp Firmware, Sg200 08 Firmware, Sg200 08p Firmware, Sf200 24 Firmware, Sf200 24p Firmware, Sf200 24fp Firmware, Sf200 48 Firmware, Sf200 48p Firmware, Sf302 08pp Firmware, Sf302 08mpp Firmware, Sg300 10pp Firmware, Sg300 10mpp Firmware, Sf300 24pp Firmware, Sf300 48pp Firmware, Sg300 28pp Firmware, Sf300 08 Firmware, Sf300 48p Firmware, Sg300 10mp Firmware, Sg300 10p Firmware, Sg300 10 Firmware, Sg300 28p Firmware, Sf300 24p Firmware, Sf302 08mp Firmware, Sg300 28 Firmware, Sf300 48 Firmware, Sg300 20 Firmware, Sf302 08p Firmware, Sg300 52 Firmware, Sf300 24 Firmware, Sf302 08 Firmware, Sf300 24mp Firmware, Sg300 10sfp Firmware, Sg300 28mp Firmware, Sg300 52p Firmware, Sg300 52mp Firmware, Sg500 28mpp Firmware, Sg500 52mp Firmware, Sg500xg 8f8t Firmware, Sf500 24 Firmware, Sf500 24p Firmware, Sf500 48 Firmware, Sf500 48p Firmware, Sg500 28 Firmware, Sg500 28p Firmware, Sg500 52 Firmware, Sg500 52p Firmware, Sg500x 24 Firmware, Sg500x 24p Firmware, Sg500x 48 Firmware, Sg500x 48p Firmware
57 products
Sg200 50 Firmware
Sg200 50p Firmware
Sg200 50fp Firmware
Sg200 26 Firmware
Sg200 26p Firmware
Sg200 26fp Firmware
Sg200 18 Firmware
Sg200 10fp Firmware
Sg200 08 Firmware
Sg200 08p Firmware
Sf200 24 Firmware
Sf200 24p Firmware
Sf200 24fp Firmware
Sf200 48 Firmware
Sf200 48p Firmware
Sf302 08pp Firmware
Sf302 08mpp Firmware
Sg300 10pp Firmware
Sg300 10mpp Firmware
Sf300 24pp Firmware
Sf300 48pp Firmware
Sg300 28pp Firmware
Sf300 08 Firmware
Sf300 48p Firmware
Sg300 10mp Firmware
Sg300 10p Firmware
Sg300 10 Firmware
Sg300 28p Firmware
Sf300 24p Firmware
Sf302 08mp Firmware
Sg300 28 Firmware
Sf300 48 Firmware
Sg300 20 Firmware
Sf302 08p Firmware
Sg300 52 Firmware
Sf300 24 Firmware
Sf302 08 Firmware
Sf300 24mp Firmware
Sg300 10sfp Firmware
Sg300 28mp Firmware
Sg300 52p Firmware
Sg300 52mp Firmware
Sg500 28mpp Firmware
Sg500 52mp Firmware
Sg500xg 8f8t Firmware
Sf500 24 Firmware
Sf500 24p Firmware
Sf500 48 Firmware
Sf500 48p Firmware
Sg500 28 Firmware
Sg500 28p Firmware
Sg500 52 Firmware
Sg500 52p Firmware
Sg500x 24 Firmware
Sg500x 24p Firmware
Sg500x 48 Firmware
Sg500x 48p Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg200 50
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg200 50p
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg200 50fp
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg200 26
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg200 26p
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg200 26fp
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg200 18
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg200 10fp
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg200 08
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg200 08p
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sf200 24
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sf200 24p
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sf200 24fp
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sf200 48
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sf200 48p
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sf302 08pp
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sf302 08mpp
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 10pp
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 10mpp
All versions
Configuration T
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sf300 24pp
All versions
Configuration U
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sf300 48pp
All versions
Configuration V
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 28pp
All versions
Configuration W
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sf300 08
All versions
Configuration X
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sf300 48p
All versions
Configuration Y
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 10mp
All versions
Configuration Z
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 10p
All versions
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 10
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 28p
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sf300 24p
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sf302 08mp
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 28
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sf300 48
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 20
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sf302 08p
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 52
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sf300 24
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sf302 08
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sf300 24mp
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 10sfp
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 28mp
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 52p
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.7.18
Running on/withPlatform Versions
Cisco
Sg300 52mp
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg500 28mpp
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg500 52mp
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg500xg 8f8t
All versions
Configuration T
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sf500 24
All versions
Configuration U
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sf500 24p
All versions
Configuration V
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sf500 48
All versions
Configuration W
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sf500 48p
All versions
Configuration X
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg500 28
All versions
Configuration Y
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg500 28p
All versions
Configuration Z
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg500 52
All versions
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg500 52p
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg500x 24
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg500x 24p
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg500x 48
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Cisco
Sg500x 48p
All versions

References (4)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.