imPC@ndo IT

Tracker / CVE-2020-3147

CVE-2020-3147

High 7.5

A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of requests sent to the web interface. An attacker could exploit this vulnerability by sending a malicious request to the web interface of an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition. This vulnerability affects firmware releases prior than 1.3.7.18

Affected products and versions

cisco sf300-08_firmware · … → 1.3.7.18
cisco sf300-24_firmware · … → 1.3.7.18
cisco sf300-24mp_firmware · … → 1.3.7.18
cisco sf300-24p_firmware · … → 1.3.7.18
cisco sf300-24pp_firmware · … → 1.3.7.18
cisco sf300-48_firmware · … → 1.3.7.18
cisco sf300-48p_firmware · … → 1.3.7.18
cisco sf300-48pp_firmware · … → 1.3.7.18
cisco sf302-08_firmware · … → 1.3.7.18
cisco sf302-08mp_firmware · … → 1.3.7.18
cisco sf302-08mpp_firmware · … → 1.3.7.18
cisco sf302-08p_firmware · … → 1.3.7.18
cisco sf302-08pp_firmware · … → 1.3.7.18
cisco sf500-24_firmware · … → 1.3.7.18
cisco sf500-24p_firmware · … → 1.3.7.18
cisco sf500-48_firmware · … → 1.3.7.18
cisco sf500-48p_firmware · … → 1.3.7.18
cisco sg200-08_firmware · … → 1.3.7.18
cisco sg200-08p_firmware · … → 1.3.7.18
cisco sg200-10fp_firmware · … → 1.3.7.18
cisco sg200-18_firmware · … → 1.3.7.18
cisco sg200-24_firmware · … → 1.3.7.18
cisco sg200-24fp_firmware · … → 1.3.7.18
cisco sg200-24p_firmware · … → 1.3.7.18
cisco sg200-26_firmware · … → 1.3.7.18
cisco sg200-26fp_firmware · … → 1.3.7.18
cisco sg200-26p_firmware · … → 1.3.7.18
cisco sg200-48_firmware · … → 1.3.7.18
cisco sg200-48p_firmware · … → 1.3.7.18
cisco sg200-50_firmware · … → 1.3.7.18
cisco sg200-50fp_firmware · … → 1.3.7.18
cisco sg200-50p_firmware · … → 1.3.7.18
cisco sg300-10_firmware · … → 1.3.7.18
cisco sg300-10mp_firmware · … → 1.3.7.18
cisco sg300-10mpp_firmware · … → 1.3.7.18
cisco sg300-10p_firmware · … → 1.3.7.18
cisco sg300-10pp_firmware · … → 1.3.7.18
cisco sg300-10sfp_firmware · … → 1.3.7.18
cisco sg300-20_firmware · … → 1.3.7.18
cisco sg300-28_firmware · … → 1.3.7.18
cisco sg300-28mp_firmware · … → 1.3.7.18
cisco sg300-28p_firmware · … → 1.3.7.18
cisco sg300-28pp_firmware · … → 1.3.7.18
cisco sg300-52_firmware · … → 1.3.7.18
cisco sg300-52mp_firmware · … → 1.3.7.18
cisco sg300-52p_firmware · … → 1.3.7.18
cisco sg500-28_firmware · … → 1.3.7.18
cisco sg500-28mpp_firmware · … → 1.3.7.18
cisco sg500-28p_firmware · … → 1.3.7.18
cisco sg500-52_firmware · … → 1.3.7.18
cisco sg500-52mp_firmware · … → 1.3.7.18
cisco sg500-52p_firmware · … → 1.3.7.18
cisco sg500x-24_firmware · … → 1.3.7.18
cisco sg500x-24p_firmware · … → 1.3.7.18
cisco sg500x-48_firmware · … → 1.3.7.18
cisco sg500x-48p_firmware · … → 1.3.7.18
cisco sg500xg-8f8t_firmware · … → 1.3.7.18

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References