// For flags

CVE-2019-1943

Cisco Small Business Series Switches Open Redirect Vulnerability

Severity Score

6.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting a user's HTTP request and modifying it into a request that causes the web interface to redirect the user to a specific malicious URL. This type of vulnerability is known as an open redirect attack and is used in phishing attacks that get users to unknowingly visit malicious sites.

Una vulnerabilidad en la interfaz web del software Cisco Small Business 200, 300 y 500 Series Switches podría permitir que un atacante remoto no autenticado redirija a un usuario a una página web maliciosa. La vulnerabilidad se debe a una validación incorrecta de entradas de los parámetros en una petición HTTP. Un atacante podría explotar esta vulnerabilidad al interceptar la solicitud HTTP de un usuario y modificarla en una solicitud que haga que la interfaz web redirija al usuario a una URL maliciosa específica. Este tipo de vulnerabilidad se conoce como ataque de redirección abierta y se usa en ataques de suplantación de identidad que hacen que los usuarios visiten sin saberlo sitios maliciosos.

Cisco Small Business switches versions 200, 300, and 500 suffer from information leakage and open redirection vulnerabilities.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2018-12-06 CVE Reserved
  • 2019-07-15 CVE Published
  • 2019-07-15 First Exploit
  • 2024-05-06 EPSS Updated
  • 2024-11-21 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Sg200-50 Firmware
Search vendor "Cisco" for product "Sg200-50 Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg200-50
Search vendor "Cisco" for product "Sg200-50"
--
Safe
Cisco
Search vendor "Cisco"
Sg200-50p Firmware
Search vendor "Cisco" for product "Sg200-50p Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg200-50p
Search vendor "Cisco" for product "Sg200-50p"
--
Safe
Cisco
Search vendor "Cisco"
Sg200-50fp Firmware
Search vendor "Cisco" for product "Sg200-50fp Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg200-50fp
Search vendor "Cisco" for product "Sg200-50fp"
--
Safe
Cisco
Search vendor "Cisco"
Sg200-26 Firmware
Search vendor "Cisco" for product "Sg200-26 Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg200-26
Search vendor "Cisco" for product "Sg200-26"
--
Safe
Cisco
Search vendor "Cisco"
Sg200-26p Firmware
Search vendor "Cisco" for product "Sg200-26p Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg200-26p
Search vendor "Cisco" for product "Sg200-26p"
--
Safe
Cisco
Search vendor "Cisco"
Sg200-26fp Firmware
Search vendor "Cisco" for product "Sg200-26fp Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg200-26fp
Search vendor "Cisco" for product "Sg200-26fp"
--
Safe
Cisco
Search vendor "Cisco"
Sg200-18 Firmware
Search vendor "Cisco" for product "Sg200-18 Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg200-18
Search vendor "Cisco" for product "Sg200-18"
--
Safe
Cisco
Search vendor "Cisco"
Sg200-10fp Firmware
Search vendor "Cisco" for product "Sg200-10fp Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg200-10fp
Search vendor "Cisco" for product "Sg200-10fp"
--
Safe
Cisco
Search vendor "Cisco"
Sg200-08 Firmware
Search vendor "Cisco" for product "Sg200-08 Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg200-08
Search vendor "Cisco" for product "Sg200-08"
--
Safe
Cisco
Search vendor "Cisco"
Sg200-08p Firmware
Search vendor "Cisco" for product "Sg200-08p Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg200-08p
Search vendor "Cisco" for product "Sg200-08p"
--
Safe
Cisco
Search vendor "Cisco"
Sf200-24 Firmware
Search vendor "Cisco" for product "Sf200-24 Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sf200-24
Search vendor "Cisco" for product "Sf200-24"
--
Safe
Cisco
Search vendor "Cisco"
Sf200-24p Firmware
Search vendor "Cisco" for product "Sf200-24p Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sf200-24p
Search vendor "Cisco" for product "Sf200-24p"
--
Safe
Cisco
Search vendor "Cisco"
Sf200-24fp Firmware
Search vendor "Cisco" for product "Sf200-24fp Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sf200-24fp
Search vendor "Cisco" for product "Sf200-24fp"
--
Safe
Cisco
Search vendor "Cisco"
Sf200-48 Firmware
Search vendor "Cisco" for product "Sf200-48 Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sf200-48
Search vendor "Cisco" for product "Sf200-48"
--
Safe
Cisco
Search vendor "Cisco"
Sf200-48p Firmware
Search vendor "Cisco" for product "Sf200-48p Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sf200-48p
Search vendor "Cisco" for product "Sf200-48p"
--
Safe
Cisco
Search vendor "Cisco"
Sf302-08pp Firmware
Search vendor "Cisco" for product "Sf302-08pp Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sf302-08pp Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sf302-08pp
Search vendor "Cisco" for product "Sf302-08pp"
--
Safe
Cisco
Search vendor "Cisco"
Sf302-08mpp Firmware
Search vendor "Cisco" for product "Sf302-08mpp Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sf302-08mpp Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sf302-08mpp
Search vendor "Cisco" for product "Sf302-08mpp"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-10pp Firmware
Search vendor "Cisco" for product "Sg300-10pp Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-10pp Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-10pp
Search vendor "Cisco" for product "Sg300-10pp"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-10mpp Firmware
Search vendor "Cisco" for product "Sg300-10mpp Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-10mpp Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-10mpp
Search vendor "Cisco" for product "Sg300-10mpp"
--
Safe
Cisco
Search vendor "Cisco"
Sf300-24pp Firmware
Search vendor "Cisco" for product "Sf300-24pp Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sf300-24pp Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sf300-24pp
Search vendor "Cisco" for product "Sf300-24pp"
--
Safe
Cisco
Search vendor "Cisco"
Sf300-48pp Firmware
Search vendor "Cisco" for product "Sf300-48pp Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sf300-48pp Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sf300-48pp
Search vendor "Cisco" for product "Sf300-48pp"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-28pp Firmware
Search vendor "Cisco" for product "Sg300-28pp Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-28pp Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-28pp
Search vendor "Cisco" for product "Sg300-28pp"
--
Safe
Cisco
Search vendor "Cisco"
Sf300-08 Firmware
Search vendor "Cisco" for product "Sf300-08 Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sf300-08 Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sf300-08
Search vendor "Cisco" for product "Sf300-08"
--
Safe
Cisco
Search vendor "Cisco"
Sf300-48p Firmware
Search vendor "Cisco" for product "Sf300-48p Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sf300-48p Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sf300-48p
Search vendor "Cisco" for product "Sf300-48p"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-10mp Firmware
Search vendor "Cisco" for product "Sg300-10mp Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-10mp Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-10mp
Search vendor "Cisco" for product "Sg300-10mp"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-10p Firmware
Search vendor "Cisco" for product "Sg300-10p Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-10p Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-10p
Search vendor "Cisco" for product "Sg300-10p"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-10 Firmware
Search vendor "Cisco" for product "Sg300-10 Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-10 Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-10
Search vendor "Cisco" for product "Sg300-10"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-28p Firmware
Search vendor "Cisco" for product "Sg300-28p Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-28p Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-28p
Search vendor "Cisco" for product "Sg300-28p"
--
Safe
Cisco
Search vendor "Cisco"
Sf300-24p Firmware
Search vendor "Cisco" for product "Sf300-24p Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sf300-24p Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sf300-24p
Search vendor "Cisco" for product "Sf300-24p"
--
Safe
Cisco
Search vendor "Cisco"
Sf302-08mp Firmware
Search vendor "Cisco" for product "Sf302-08mp Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sf302-08mp Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sf302-08mp
Search vendor "Cisco" for product "Sf302-08mp"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-28 Firmware
Search vendor "Cisco" for product "Sg300-28 Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-28 Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-28
Search vendor "Cisco" for product "Sg300-28"
--
Safe
Cisco
Search vendor "Cisco"
Sf300-48 Firmware
Search vendor "Cisco" for product "Sf300-48 Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sf300-48 Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sf300-48
Search vendor "Cisco" for product "Sf300-48"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-20 Firmware
Search vendor "Cisco" for product "Sg300-20 Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-20 Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-20
Search vendor "Cisco" for product "Sg300-20"
--
Safe
Cisco
Search vendor "Cisco"
Sf302-08p Firmware
Search vendor "Cisco" for product "Sf302-08p Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sf302-08p Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sf302-08p
Search vendor "Cisco" for product "Sf302-08p"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-52 Firmware
Search vendor "Cisco" for product "Sg300-52 Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-52 Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-52
Search vendor "Cisco" for product "Sg300-52"
--
Safe
Cisco
Search vendor "Cisco"
Sf300-24 Firmware
Search vendor "Cisco" for product "Sf300-24 Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sf300-24 Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sf300-24
Search vendor "Cisco" for product "Sf300-24"
--
Safe
Cisco
Search vendor "Cisco"
Sf302-08 Firmware
Search vendor "Cisco" for product "Sf302-08 Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sf302-08 Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sf302-08
Search vendor "Cisco" for product "Sf302-08"
--
Safe
Cisco
Search vendor "Cisco"
Sf300-24mp Firmware
Search vendor "Cisco" for product "Sf300-24mp Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sf300-24mp Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sf300-24mp
Search vendor "Cisco" for product "Sf300-24mp"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-10sfp Firmware
Search vendor "Cisco" for product "Sg300-10sfp Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-10sfp Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-10sfp
Search vendor "Cisco" for product "Sg300-10sfp"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-28mp Firmware
Search vendor "Cisco" for product "Sg300-28mp Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-28mp Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-28mp
Search vendor "Cisco" for product "Sg300-28mp"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-52p Firmware
Search vendor "Cisco" for product "Sg300-52p Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-52p Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-52p
Search vendor "Cisco" for product "Sg300-52p"
--
Safe
Cisco
Search vendor "Cisco"
Sg300-52mp Firmware
Search vendor "Cisco" for product "Sg300-52mp Firmware"
1.3.7.18
Search vendor "Cisco" for product "Sg300-52mp Firmware" and version "1.3.7.18"
-
Affected
in Cisco
Search vendor "Cisco"
Sg300-52mp
Search vendor "Cisco" for product "Sg300-52mp"
--
Safe
Cisco
Search vendor "Cisco"
Sg500-28mpp Firmware
Search vendor "Cisco" for product "Sg500-28mpp Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg500-28mpp
Search vendor "Cisco" for product "Sg500-28mpp"
--
Safe
Cisco
Search vendor "Cisco"
Sg500-52mp Firmware
Search vendor "Cisco" for product "Sg500-52mp Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg500-52mp
Search vendor "Cisco" for product "Sg500-52mp"
--
Safe
Cisco
Search vendor "Cisco"
Sg500xg-8f8t Firmware
Search vendor "Cisco" for product "Sg500xg-8f8t Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg500xg-8f8t
Search vendor "Cisco" for product "Sg500xg-8f8t"
--
Safe
Cisco
Search vendor "Cisco"
Sf500-24 Firmware
Search vendor "Cisco" for product "Sf500-24 Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sf500-24
Search vendor "Cisco" for product "Sf500-24"
--
Safe
Cisco
Search vendor "Cisco"
Sf500-24p Firmware
Search vendor "Cisco" for product "Sf500-24p Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sf500-24p
Search vendor "Cisco" for product "Sf500-24p"
--
Safe
Cisco
Search vendor "Cisco"
Sf500-48 Firmware
Search vendor "Cisco" for product "Sf500-48 Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sf500-48
Search vendor "Cisco" for product "Sf500-48"
--
Safe
Cisco
Search vendor "Cisco"
Sf500-48p Firmware
Search vendor "Cisco" for product "Sf500-48p Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sf500-48p
Search vendor "Cisco" for product "Sf500-48p"
--
Safe
Cisco
Search vendor "Cisco"
Sg500-28 Firmware
Search vendor "Cisco" for product "Sg500-28 Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg500-28
Search vendor "Cisco" for product "Sg500-28"
--
Safe
Cisco
Search vendor "Cisco"
Sg500-28p Firmware
Search vendor "Cisco" for product "Sg500-28p Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg500-28p
Search vendor "Cisco" for product "Sg500-28p"
--
Safe
Cisco
Search vendor "Cisco"
Sg500-52 Firmware
Search vendor "Cisco" for product "Sg500-52 Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg500-52
Search vendor "Cisco" for product "Sg500-52"
--
Safe
Cisco
Search vendor "Cisco"
Sg500-52p Firmware
Search vendor "Cisco" for product "Sg500-52p Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg500-52p
Search vendor "Cisco" for product "Sg500-52p"
--
Safe
Cisco
Search vendor "Cisco"
Sg500x-24 Firmware
Search vendor "Cisco" for product "Sg500x-24 Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg500x-24
Search vendor "Cisco" for product "Sg500x-24"
--
Safe
Cisco
Search vendor "Cisco"
Sg500x-24p Firmware
Search vendor "Cisco" for product "Sg500x-24p Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg500x-24p
Search vendor "Cisco" for product "Sg500x-24p"
--
Safe
Cisco
Search vendor "Cisco"
Sg500x-48 Firmware
Search vendor "Cisco" for product "Sg500x-48 Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg500x-48
Search vendor "Cisco" for product "Sg500x-48"
--
Safe
Cisco
Search vendor "Cisco"
Sg500x-48p Firmware
Search vendor "Cisco" for product "Sg500x-48p Firmware"
--
Affected
in Cisco
Search vendor "Cisco"
Sg500x-48p
Search vendor "Cisco" for product "Sg500x-48p"
--
Safe