peter bassill · operator
$ cve CVE-2019-1943 JSON

CVE-2019-1943 EXPLOIT

4.7
MEDIUM · CVSS 3.0 · EPSS 9.7% (pctl 95)

Patch early

A public exploit exists.

Description

A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting a user's HTTP request and modifying it into a request that causes the web interface to redirect the user to a specific malicious URL. This type of vulnerability is known as an open redirect attack and is used in phishing attacks that get users to unknowingly visit malicious sites.

Scoring

CVSS4.7 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS9.69% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-601
On CISA KEVno
Public exploityes
Published2019-07-17
Last modified2026-06-17

Affected (40)

VendorProduct
ciscosf200-24
ciscosf200-24 firmware
ciscosf200-24fp
ciscosf200-24fp firmware
ciscosf200-24p
ciscosf200-24p firmware
ciscosf200-48
ciscosf200-48 firmware
ciscosf200-48p
ciscosf200-48p firmware
ciscosf300-24pp
ciscosf300-24pp firmware
ciscosf302-08mpp
ciscosf302-08mpp firmware
ciscosf302-08pp
ciscosf302-08pp firmware
ciscosg200-08
ciscosg200-08 firmware
ciscosg200-08p
ciscosg200-08p firmware
ciscosg200-10fp
ciscosg200-10fp firmware
ciscosg200-18
ciscosg200-18 firmware
ciscosg200-26
ciscosg200-26 firmware
ciscosg200-26fp
ciscosg200-26fp firmware
ciscosg200-26p
ciscosg200-26p firmware
ciscosg200-50
ciscosg200-50 firmware
ciscosg200-50fp
ciscosg200-50fp firmware
ciscosg200-50p
ciscosg200-50p firmware
ciscosg300-10mpp
ciscosg300-10mpp firmware
ciscosg300-10pp
ciscosg300-10pp firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD