Critical Vulnerabilities in Cisco Small Business Series Switches

Four vulnerabilities have been discovered in Cisco's Small Business series switches, allowing a remote attacker to gain full root access to the device without authentication. To exploit these issues, the attacker must be able to send requests to the network port that operates the web interface. The vulnerabilities are rated as critical (9.8 out of 10). A working exploit prototype has been reported.

The identified vulnerabilities (CVE-2023-20159, CVE-2023-20160, CVE-2023-20161, CVE-2023-20189) are caused by memory handling errors in various handlers available before authentication occurs. These vulnerabilities lead to buffer overflows when processing specially crafted external data. Additionally, four less severe vulnerabilities (CVE-2023-20024, CVE-2023-20156, CVE-2023-20157, CVE-2023-20158) allow for remote denial of service initiation, and one vulnerability (CVE-2023-20162) enables access to device configuration information without authentication.

The vulnerabilities affect the Smart Switch series 250, 350, 350X, 550X, Business 250, and Business 350, as well as the Small Business series 200, 300, and 500. The series 220 and Business 220 switches do not exhibit the vulnerability. The issues have been resolved in firmware updates 2.5.9.16 and 3.3.0.16. No firmware updates will be made for the Small Business series 200, 300, and 500, as the lifecycle of these models has already ended.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster