peter bassill · operator
$ cve CVE-2019-15993 JSON

CVE-2019-15993 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 10.3% (pctl 96)

Patch early

A public exploit exists.

Description

A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible from the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web UI of an affected device. A successful exploit could allow the attacker to access sensitive device information, which includes configuration files.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS10.27% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-16
On CISA KEVno
Public exploityes
Published2020-09-23
Last modified2026-06-17

Affected (40)

VendorProduct
ciscosf250-24
ciscosf250-24 firmware
ciscosf250-24p
ciscosf250-24p firmware
ciscosf250-48
ciscosf250-48 firmware
ciscosf250-48hp
ciscosf250-48hp firmware
ciscosg250-08
ciscosg250-08 firmware
ciscosg250-08hp
ciscosg250-08hp firmware
ciscosg250-10p
ciscosg250-10p firmware
ciscosg250-18
ciscosg250-18 firmware
ciscosg250-26
ciscosg250-26 firmware
ciscosg250-26hp
ciscosg250-26hp firmware
ciscosg250-26p
ciscosg250-26p firmware
ciscosg250-50
ciscosg250-50 firmware
ciscosg250-50hp
ciscosg250-50hp firmware
ciscosg250-50p
ciscosg250-50p firmware
ciscosg250x-24
ciscosg250x-24 firmware
ciscosg250x-24p
ciscosg250x-24p firmware
ciscosg250x-48
ciscosg250x-48 firmware
ciscosg250x-48p
ciscosg250x-48p firmware
ciscosg350-10
ciscosg350-10 firmware
ciscosg350-10p
ciscosg350-10p firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD