9.8
CVSSv3

CVE-2023-20161

Published: 18/05/2023 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote malicious user to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco business 250-16p-2g firmware -

cisco business 250-16t-2g firmware -

cisco business 250-24fp-4g firmware -

cisco business 250-24fp-4x firmware -

cisco business 250-24p-4g firmware -

cisco business 250-24p-4x firmware -

cisco business 250-24pp-4g firmware -

cisco business 250-24t-4g firmware -

cisco business 250-24t-4x firmware -

cisco business 250-48p-4g firmware -

cisco business 250-48p-4x firmware -

cisco business 250-48pp-4g firmware -

cisco business 250-48t-4g firmware -

cisco business 250-48t-4x firmware -

cisco business 250-8fp-e-2g firmware -

cisco business 250-8p-e-2g firmware -

cisco business 250-8pp-d firmware -

cisco business 250-8pp-e-2g firmware -

cisco business 250-8t-d firmware -

cisco business 250-8t-e-2g firmware -

cisco business 350-12np-4x firmware -

cisco business 350-12xs firmware -

cisco business 350-12xt firmware -

cisco business 350-16fp-2g firmware -

cisco business 350-16p-2g firmware -

cisco business 350-16p-e-2g firmware -

cisco business 350-16t-2g firmware -

cisco business 350-16t-e-2g firmware -

cisco business 350-16xts firmware -

cisco business 350-24fp-4g firmware -

cisco business 350-24fp-4x firmware -

cisco business 350-24mgp-4x firmware -

cisco business 350-24ngp-4x firmware -

cisco business 350-24p-4g firmware -

cisco business 350-24p-4x firmware -

cisco business 350-24s-4g firmware -

cisco business 350-24t-4g firmware -

cisco business 350-24t-4x firmware -

cisco business 350-24xs firmware -

cisco business 350-24xt firmware -

cisco business 350-24xts firmware -

cisco business 350-48fp-4g firmware -

cisco business 350-48fp-4x firmware -

cisco business 350-48ngp-4x firmware -

cisco business 350-48p-4g firmware -

cisco business 350-48p-4x firmware -

cisco business 350-48t-4g firmware -

cisco business 350-48t-4x firmware -

cisco business 350-48xt-4x firmware -

cisco business 350-8fp-2g firmware -

cisco business 350-8fp-e-2g firmware -

cisco business 350-8mgp-2x firmware -

cisco business 350-8mp-2x firmware -

cisco business 350-8p-2g firmware -

cisco business 350-8p-e-2g firmware -

cisco business 350-8s-e-2g firmware -

cisco business 350-8t-e-2g firmware -

cisco business 350-8xt firmware -

cisco sf200-24 firmware -

cisco sf200-24fp firmware -

cisco sf200-24p firmware -

cisco sf200-48 firmware -

cisco sf200-48p firmware -

cisco sf200e-24 firmware -

cisco sf200e-24p firmware -

cisco sf200e-48 firmware -

cisco sf200e-48p firmware -

cisco sf200e48p firmware -

cisco sf250-08 firmware -

cisco sf250-08hp firmware -

cisco sf250-10p firmware -

cisco sf250-18 firmware -

cisco sf250-24 firmware -

cisco sf250-24p firmware -

cisco sf250-26 firmware -

cisco sf250-26hp firmware -

cisco sf250-26p firmware -

cisco sf250-48 firmware -

cisco sf250-48hp firmware -

cisco sf250-50 firmware -

cisco sf250-50hp firmware -

cisco sf250-50p firmware -

cisco sf250x-24 firmware -

cisco sf250x-24p firmware -

cisco sf250x-48 firmware -

cisco sf250x-48p firmware -

cisco sf300-08 firmware -

cisco sf300-24 firmware -

cisco sf300-24mp firmware -

cisco sf300-24p firmware -

cisco sf300-24pp firmware -

cisco sf300-48 firmware -

cisco sf300-48p firmware -

cisco sf300-48pp firmware -

cisco sf302-08 firmware -

cisco sf302-08mpp firmware -

cisco sf302-08pp firmware -

cisco sf350-08 firmware -

cisco sf350-10 firmware -

cisco sf350-10mp firmware -

cisco sf350-10p firmware -

cisco sf350-10sfp firmware -

cisco sf350-20 firmware -

cisco sf350-24 firmware -

cisco sf350-24mp firmware -

cisco sf350-24p firmware -

cisco sf350-28 firmware -

cisco sf350-28mp firmware -

cisco sf350-28p firmware -

cisco sf350-28sfp firmware -

cisco sf350-48 firmware -

cisco sf350-48mp firmware -

cisco sf350-48p firmware -

cisco sf350-52 firmware -

cisco sf350-52mp firmware -

cisco sf350-52p firmware -

cisco sf350-8mp firmware -

cisco sf350-8pd firmware -

cisco sf352-08 firmware -

cisco sf352-08mp firmware -

cisco sf352-08p firmware -

cisco sf355-10p firmware -

cisco sf500-18p firmware -

cisco sf500-24 firmware -

cisco sf500-24mp firmware -

cisco sf500-24p firmware -

cisco sf500-48 firmware -

cisco sf500-48mp firmware -

cisco sf500-48p firmware -

cisco sf550x-24 firmware -

cisco sf550x-24mp firmware -

cisco sf550x-24p firmware -

cisco sf550x-48 firmware -

cisco sf550x-48mp firmware -

cisco sf550x-48p firmware -

cisco sg200-08 firmware -

cisco sg200-08p firmware -

cisco sg200-10fp firmware -

cisco sg200-18 firmware -

cisco sg200-26 firmware -

cisco sg200-26fp firmware -

cisco sg200-26p firmware -

cisco sg200-50 firmware -

cisco sg200-50fp firmware -

cisco sg200-50p firmware -

cisco sg250-08 firmware -

cisco sg250-08hp firmware -

cisco sg250-10p firmware -

cisco sg250-18 firmware -

cisco sg250-24 firmware -

cisco sg250-24p firmware -

cisco sg250-26 firmware -

cisco sg250-26hp firmware -

cisco sg250-26p firmware -

cisco sg250-48 firmware -

cisco sg250-48hp firmware -

cisco sg250-50 firmware -

cisco sg250-50hp firmware -

cisco sg250-50p firmware -

cisco sg250x-24 firmware -

cisco sg250x-24p firmware -

cisco sg250x-48 firmware -

cisco sg250x-48p firmware -

cisco sg300-10 firmware -

cisco sg300-10mp firmware -

cisco sg300-10mpp firmware -

cisco sg300-10p firmware -

cisco sg300-10pp firmware -

cisco sg300-10sfp firmware -

cisco sg300-20 firmware -

cisco sg300-28 firmware -

cisco sg300-28mp firmware -

cisco sg300-28p firmware -

cisco sg300-28pp firmware -

cisco sg300-28sfp firmware -

cisco sg300-52 firmware -

cisco sg300-52mp firmware -

cisco sg300-52p firmware -

cisco sg350-10 firmware -

cisco sg350-10mp firmware -

cisco sg350-10p firmware -

cisco sg350-28 firmware -

cisco sg350-28mp firmware -

cisco sg350-28p firmware -

cisco sg350x-12pmv firmware -

cisco sg350x-24 firmware -

cisco sg350x-24mp firmware -

cisco sg350x-24p firmware -

cisco sg350x-24pd firmware -

cisco sg350x-24pv firmware -

cisco sg350x-48 firmware -

cisco sg350x-48mp firmware -

cisco sg350x-48p firmware -

cisco sg350x-48pv firmware -

cisco sg350x-8pmd firmware -

cisco sg350xg-24f firmware -

cisco sg350xg-24t firmware -

cisco sg350xg-2f10 firmware -

cisco sg350xg-48t firmware -

cisco sg355-10mp firmware -

cisco sg355-10p firmware -

cisco sg500-28 firmware -

cisco sg500-28mpp firmware -

cisco sg500-28p firmware -

cisco sg500-28pp firmware -

cisco sg500-52p firmware -

cisco sg500-52pp firmware -

cisco sg500x-24 firmware -

cisco sg500x-24mpp firmware -

cisco sg500x-24p firmware -

cisco sg500x-48 firmware -

cisco sg500x-48mp firmware -

cisco sg500x-48mpp firmware -

cisco sg500x-48p firmware -

cisco sg500x24mpp firmware -

cisco sg500xg-8f8t firmware -

cisco sg500xg8f8t firmware -

cisco sg550x-24 firmware -

cisco sg550x-24mp firmware -

cisco sg550x-24mpp firmware -

cisco sg550x-24p firmware -

cisco sg550x-48 firmware -

cisco sg550x-48mp firmware -

cisco sg550x-48p firmware -

cisco sg550x-48t firmware -

cisco sg550xg-24f firmware -

cisco sg550xg-24t firmware -

cisco sg550xg-48t firmware -

cisco sg550xg-8f8t firmware -

Vendor Advisories

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device These vulnerabilities are due to improper validation of requests that are sent to ...

Recent Articles

Cisco squashes critical bugs in small biz switches
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources You'll want to patch these as proof-of-concept exploit code is out there already

Cisco rolled out patches for four critical security vulnerabilities in several of its network switches for small businesses that can be exploited to remotely hijack the equipment. Specifically, the flaws in the web user interface can be used to run arbitrary code with root privileges. The networking giant this week said in an advisory that organizations with service contracts that include regular software updates should get fixes for the security holes through their usual update channels. Those ...