#VU19026 Buffer overflow in Cisco Systems, Inc products - CVE-2019-1892
Published: July 8, 2019
Vulnerability identifier: #VU19026
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-1892
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Cisco Small Business 500 Series Stackable Managed Switches
Cisco Small Business 300 Series Managed Switches
Cisco Small Business 200 Series Smart Switches
Cisco Small Business 500 Series Stackable Managed Switches
Cisco Small Business 300 Series Managed Switches
Cisco Small Business 200 Series Smart Switches
Software vendor:
Cisco Systems, Inc
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to cause a memory corruption on affected devices.
The vulnerability exists due to improper validation of HTTPS packets in the Secure Sockets Layer (SSL) input packet processor. A remote attacker can send a malformed HTTPS packet to the management web interface and cause an unexpected reload of the devices, resulting in a denial of service (DoS) condition.
Remediation
Install updates from vendor's website.