CVE-2021-40127
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an unauthenticated, remote attacker to render the web-based management interface unusable, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to cause a permanent invalid redirect for requests sent to the web-based management interface of the device, resulting in a DoS condition.
Affected (66)
Products: Cisco: Sf200 24 Firmware, Sf200 24fp Firmware, Sf200 24p Firmware, Sf200 48 Firmware, Sf200 48p Firmware, Sf200e 24 Firmware, Sf200e 24p Firmware, Sf200e 48 Firmware, Sf200e 48p Firmware, Sg200 08 Firmware, Sg200 08p Firmware, Sg200 10fp Firmware, Sg200 18 Firmware, Sg200 26 Firmware, Sg200 26fp Firmware, Sg200 26p Firmware, Sg200 50 Firmware, Sg200 50fp Firmware, Sg200 50p Firmware, Sf300 08 Firmware, Sf300 24 Firmware, Sf300 24mp Firmware, Sf300 24p Firmware, Sf300 24pp Firmware, Sf300 48 Firmware, Sf300 48p Firmware, Sf300 48pp Firmware, Sf302 08 Firmware, Sf302 08mp Firmware, Sf302 08mpp Firmware, Sf302 08p Firmware, Sf302 08pp Firmware, Sg300 10 Firmware, Sg300 10mp Firmware, Sg300 10mpp Firmware, Sg300 10p Firmware, Sg300 10pp Firmware, Sg300 Sfp Firmware, Sg300 20 Firmware, Sg300 28 Firmware, Sg300 28mp Firmware, Sg300 28p Firmware, Sg300 28pp Firmware, Sg300 28sfp Firmware, Sg300 52 Firmware, Sg300 52mp Firmware, Sg300 52p Firmware, Sf500 24 Firmware, Sf500 24mp Firmware, Sf500 24p Firmware, Sf500 48 Firmware, Sf500 48mp Firmware, Sf500 48p Firmware, Sg500 28 Firmware, Sg500 28mpp Firmware, Sg500 28p Firmware, Sg500 52 Firmware, Sg500 52mp Firmware, Sg500 52p Firmware, Sg500x 24 Firmware, Sg500x 24mpp Firmware, Sg500x 24p Firmware, Sg500x 48 Firmware, Sg500x 48mpp Firmware, Sg500x 48p Firmware, Sg500xg 8f8t Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf200 24 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf200 24fp | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf200 24p | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf200 48 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf200 48p | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf200e 24 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf200e 24p | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf200e 48 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf200e 48p | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg200 08 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg200 08p | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg200 10fp | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg200 18 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg200 26 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg200 26fp | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg200 26p | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg200 50 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg200 50fp | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg200 50p | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 08 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 24 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 24mp | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 24p | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 24pp | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 48 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 48p | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf300 48pp | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf302 08 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf302 08mp | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf302 08mpp | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf302 08p | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf302 08pp | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 10 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 10mp | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 10mpp | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 10p | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 10pp | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 Sfp | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 20 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 28 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 28mp | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 28p | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 28pp | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 28sfp | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 52 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 52mp | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.4.11.02 |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg300 52p | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf500 24 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf500 24mp | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf500 24p | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf500 48 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf500 48mp | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sf500 48p | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500 28 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500 28mpp | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500 28p | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500 52 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500 52mp | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500 52p | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500x 24 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500x 24mpp | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500x 24p | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500x 48 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500x 48mpp | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500x 48p | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Cisco Sg500xg 8f8t | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.