
CVE-2019-1892 – Cisco Small Business Series Switches Memory Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2019-1892
06 Jul 2019 — A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a memory corruption on an affected device. The vulnerability is due to improper validation of HTTPS packets. An attacker could exploit this vulnerability by sending a malformed HTTPS packet to the management web interface of the affected device. A successful exploit could allow the attacker to cause an unexpected r... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-sbss-memcorrupt • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2019-1806 – Cisco Small Business Series Switches Simple Network Management Protocol Denial of Service Vulnerability
https://notcve.org/view.php?id=CVE-2019-1806
15 May 2019 — A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches could allow an authenticated, remote attacker to cause the SNMP application of an affected device to cease processing traffic, resulting in the CPU utilization reaching one hundred percent. Manual intervention may be required before a device resumes normal operations. The vulnerability is due t... • http://www.securityfocus.com/bid/108335 • CWE-20: Improper Input Validation CWE-770: Allocation of Resources Without Limits or Throttling •