CVE-2019-1943
Cisco Small Business Series Switches Open Redirect Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting a user's HTTP request and modifying it into a request that causes the web interface to redirect the user to a specific malicious URL. This type of vulnerability is known as an open redirect attack and is used in phishing attacks that get users to unknowingly visit malicious sites.
Una vulnerabilidad en la interfaz web del software Cisco Small Business 200, 300 y 500 Series Switches podría permitir que un atacante remoto no autenticado redirija a un usuario a una página web maliciosa. La vulnerabilidad se debe a una validación incorrecta de entradas de los parámetros en una petición HTTP. Un atacante podría explotar esta vulnerabilidad al interceptar la solicitud HTTP de un usuario y modificarla en una solicitud que haga que la interfaz web redirija al usuario a una URL maliciosa específica. Este tipo de vulnerabilidad se conoce como ataque de redirección abierta y se usa en ataques de suplantación de identidad que hacen que los usuarios visiten sin saberlo sitios maliciosos.
Cisco Small Business switches versions 200, 300, and 500 suffer from information leakage and open redirection vulnerabilities.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2018-12-06 CVE Reserved
- 2019-07-15 CVE Published
- 2019-07-15 First Exploit
- 2024-05-06 EPSS Updated
- 2024-11-21 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/109288 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/47118 | 2019-07-15 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Sg200-50 Firmware Search vendor "Cisco" for product "Sg200-50 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg200-50 Search vendor "Cisco" for product "Sg200-50" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg200-50p Firmware Search vendor "Cisco" for product "Sg200-50p Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg200-50p Search vendor "Cisco" for product "Sg200-50p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg200-50fp Firmware Search vendor "Cisco" for product "Sg200-50fp Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg200-50fp Search vendor "Cisco" for product "Sg200-50fp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg200-26 Firmware Search vendor "Cisco" for product "Sg200-26 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg200-26 Search vendor "Cisco" for product "Sg200-26" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg200-26p Firmware Search vendor "Cisco" for product "Sg200-26p Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg200-26p Search vendor "Cisco" for product "Sg200-26p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg200-26fp Firmware Search vendor "Cisco" for product "Sg200-26fp Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg200-26fp Search vendor "Cisco" for product "Sg200-26fp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg200-18 Firmware Search vendor "Cisco" for product "Sg200-18 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg200-18 Search vendor "Cisco" for product "Sg200-18" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg200-10fp Firmware Search vendor "Cisco" for product "Sg200-10fp Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg200-10fp Search vendor "Cisco" for product "Sg200-10fp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg200-08 Firmware Search vendor "Cisco" for product "Sg200-08 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg200-08 Search vendor "Cisco" for product "Sg200-08" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg200-08p Firmware Search vendor "Cisco" for product "Sg200-08p Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg200-08p Search vendor "Cisco" for product "Sg200-08p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf200-24 Firmware Search vendor "Cisco" for product "Sf200-24 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf200-24 Search vendor "Cisco" for product "Sf200-24" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf200-24p Firmware Search vendor "Cisco" for product "Sf200-24p Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf200-24p Search vendor "Cisco" for product "Sf200-24p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf200-24fp Firmware Search vendor "Cisco" for product "Sf200-24fp Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf200-24fp Search vendor "Cisco" for product "Sf200-24fp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf200-48 Firmware Search vendor "Cisco" for product "Sf200-48 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf200-48 Search vendor "Cisco" for product "Sf200-48" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf200-48p Firmware Search vendor "Cisco" for product "Sf200-48p Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf200-48p Search vendor "Cisco" for product "Sf200-48p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf302-08pp Firmware Search vendor "Cisco" for product "Sf302-08pp Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sf302-08pp Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf302-08pp Search vendor "Cisco" for product "Sf302-08pp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf302-08mpp Firmware Search vendor "Cisco" for product "Sf302-08mpp Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sf302-08mpp Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf302-08mpp Search vendor "Cisco" for product "Sf302-08mpp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-10pp Firmware Search vendor "Cisco" for product "Sg300-10pp Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-10pp Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-10pp Search vendor "Cisco" for product "Sg300-10pp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-10mpp Firmware Search vendor "Cisco" for product "Sg300-10mpp Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-10mpp Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-10mpp Search vendor "Cisco" for product "Sg300-10mpp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf300-24pp Firmware Search vendor "Cisco" for product "Sf300-24pp Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sf300-24pp Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf300-24pp Search vendor "Cisco" for product "Sf300-24pp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf300-48pp Firmware Search vendor "Cisco" for product "Sf300-48pp Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sf300-48pp Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf300-48pp Search vendor "Cisco" for product "Sf300-48pp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-28pp Firmware Search vendor "Cisco" for product "Sg300-28pp Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-28pp Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-28pp Search vendor "Cisco" for product "Sg300-28pp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf300-08 Firmware Search vendor "Cisco" for product "Sf300-08 Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sf300-08 Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf300-08 Search vendor "Cisco" for product "Sf300-08" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf300-48p Firmware Search vendor "Cisco" for product "Sf300-48p Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sf300-48p Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf300-48p Search vendor "Cisco" for product "Sf300-48p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-10mp Firmware Search vendor "Cisco" for product "Sg300-10mp Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-10mp Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-10mp Search vendor "Cisco" for product "Sg300-10mp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-10p Firmware Search vendor "Cisco" for product "Sg300-10p Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-10p Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-10p Search vendor "Cisco" for product "Sg300-10p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-10 Firmware Search vendor "Cisco" for product "Sg300-10 Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-10 Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-10 Search vendor "Cisco" for product "Sg300-10" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-28p Firmware Search vendor "Cisco" for product "Sg300-28p Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-28p Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-28p Search vendor "Cisco" for product "Sg300-28p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf300-24p Firmware Search vendor "Cisco" for product "Sf300-24p Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sf300-24p Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf300-24p Search vendor "Cisco" for product "Sf300-24p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf302-08mp Firmware Search vendor "Cisco" for product "Sf302-08mp Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sf302-08mp Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf302-08mp Search vendor "Cisco" for product "Sf302-08mp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-28 Firmware Search vendor "Cisco" for product "Sg300-28 Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-28 Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-28 Search vendor "Cisco" for product "Sg300-28" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf300-48 Firmware Search vendor "Cisco" for product "Sf300-48 Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sf300-48 Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf300-48 Search vendor "Cisco" for product "Sf300-48" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-20 Firmware Search vendor "Cisco" for product "Sg300-20 Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-20 Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-20 Search vendor "Cisco" for product "Sg300-20" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf302-08p Firmware Search vendor "Cisco" for product "Sf302-08p Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sf302-08p Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf302-08p Search vendor "Cisco" for product "Sf302-08p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-52 Firmware Search vendor "Cisco" for product "Sg300-52 Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-52 Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-52 Search vendor "Cisco" for product "Sg300-52" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf300-24 Firmware Search vendor "Cisco" for product "Sf300-24 Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sf300-24 Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf300-24 Search vendor "Cisco" for product "Sf300-24" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf302-08 Firmware Search vendor "Cisco" for product "Sf302-08 Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sf302-08 Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf302-08 Search vendor "Cisco" for product "Sf302-08" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf300-24mp Firmware Search vendor "Cisco" for product "Sf300-24mp Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sf300-24mp Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf300-24mp Search vendor "Cisco" for product "Sf300-24mp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-10sfp Firmware Search vendor "Cisco" for product "Sg300-10sfp Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-10sfp Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-10sfp Search vendor "Cisco" for product "Sg300-10sfp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-28mp Firmware Search vendor "Cisco" for product "Sg300-28mp Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-28mp Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-28mp Search vendor "Cisco" for product "Sg300-28mp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-52p Firmware Search vendor "Cisco" for product "Sg300-52p Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-52p Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-52p Search vendor "Cisco" for product "Sg300-52p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg300-52mp Firmware Search vendor "Cisco" for product "Sg300-52mp Firmware" | 1.3.7.18 Search vendor "Cisco" for product "Sg300-52mp Firmware" and version "1.3.7.18" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg300-52mp Search vendor "Cisco" for product "Sg300-52mp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg500-28mpp Firmware Search vendor "Cisco" for product "Sg500-28mpp Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg500-28mpp Search vendor "Cisco" for product "Sg500-28mpp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg500-52mp Firmware Search vendor "Cisco" for product "Sg500-52mp Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg500-52mp Search vendor "Cisco" for product "Sg500-52mp" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg500xg-8f8t Firmware Search vendor "Cisco" for product "Sg500xg-8f8t Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg500xg-8f8t Search vendor "Cisco" for product "Sg500xg-8f8t" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf500-24 Firmware Search vendor "Cisco" for product "Sf500-24 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf500-24 Search vendor "Cisco" for product "Sf500-24" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf500-24p Firmware Search vendor "Cisco" for product "Sf500-24p Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf500-24p Search vendor "Cisco" for product "Sf500-24p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf500-48 Firmware Search vendor "Cisco" for product "Sf500-48 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf500-48 Search vendor "Cisco" for product "Sf500-48" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sf500-48p Firmware Search vendor "Cisco" for product "Sf500-48p Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sf500-48p Search vendor "Cisco" for product "Sf500-48p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg500-28 Firmware Search vendor "Cisco" for product "Sg500-28 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg500-28 Search vendor "Cisco" for product "Sg500-28" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg500-28p Firmware Search vendor "Cisco" for product "Sg500-28p Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg500-28p Search vendor "Cisco" for product "Sg500-28p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg500-52 Firmware Search vendor "Cisco" for product "Sg500-52 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg500-52 Search vendor "Cisco" for product "Sg500-52" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg500-52p Firmware Search vendor "Cisco" for product "Sg500-52p Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg500-52p Search vendor "Cisco" for product "Sg500-52p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg500x-24 Firmware Search vendor "Cisco" for product "Sg500x-24 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg500x-24 Search vendor "Cisco" for product "Sg500x-24" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg500x-24p Firmware Search vendor "Cisco" for product "Sg500x-24p Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg500x-24p Search vendor "Cisco" for product "Sg500x-24p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg500x-48 Firmware Search vendor "Cisco" for product "Sg500x-48 Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg500x-48 Search vendor "Cisco" for product "Sg500x-48" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sg500x-48p Firmware Search vendor "Cisco" for product "Sg500x-48p Firmware" | - | - |
Affected
| in | Cisco Search vendor "Cisco" | Sg500x-48p Search vendor "Cisco" for product "Sg500x-48p" | - | - |
Safe
|