CVE-2019-15993 EXPLOIT
5.3
MEDIUM · CVSS 3.1 · EPSS 10.3% (pctl 96)
Patch early
A public exploit exists.
Description
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible from the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web UI of an affected device. A successful exploit could allow the attacker to access sensitive device information, which includes configuration files.
Scoring
| CVSS | 5.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 10.27% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-16 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-09-23 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| cisco | sf250-24 |
| cisco | sf250-24 firmware |
| cisco | sf250-24p |
| cisco | sf250-24p firmware |
| cisco | sf250-48 |
| cisco | sf250-48 firmware |
| cisco | sf250-48hp |
| cisco | sf250-48hp firmware |
| cisco | sg250-08 |
| cisco | sg250-08 firmware |
| cisco | sg250-08hp |
| cisco | sg250-08hp firmware |
| cisco | sg250-10p |
| cisco | sg250-10p firmware |
| cisco | sg250-18 |
| cisco | sg250-18 firmware |
| cisco | sg250-26 |
| cisco | sg250-26 firmware |
| cisco | sg250-26hp |
| cisco | sg250-26hp firmware |
| cisco | sg250-26p |
| cisco | sg250-26p firmware |
| cisco | sg250-50 |
| cisco | sg250-50 firmware |
| cisco | sg250-50hp |
| cisco | sg250-50hp firmware |
| cisco | sg250-50p |
| cisco | sg250-50p firmware |
| cisco | sg250x-24 |
| cisco | sg250x-24 firmware |
| cisco | sg250x-24p |
| cisco | sg250x-24p firmware |
| cisco | sg250x-48 |
| cisco | sg250x-48 firmware |
| cisco | sg250x-48p |
| cisco | sg250x-48p firmware |
| cisco | sg350-10 |
| cisco | sg350-10 firmware |
| cisco | sg350-10p |
| cisco | sg350-10p firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB - Information Disclosure | 2023-04-05 |
References
- http://packetstormsecurity.com/files/171723/Cisco-Dell-Netgear-Information-Disclosure-Hash-Decrypter.html
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200129-smlbus-switch-disclos
- http://packetstormsecurity.com/files/171723/Cisco-Dell-Netgear-Information-Disclosure-Hash-Decrypter.html
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200129-smlbus-switch-disclos
→ the Explorer · watch your stack · NVD