CVE-2016-1299: Medium severity cisco small business 300 series managed switches vulnerability
Published Jan 27, 2016
·Updated
The web-management GUI implementation on Cisco Small Business SG300 devices 1.4.1.x allows remote attackers to cause a denial of service (HTTPS outage) via crafted HTTPS requests, aka Bug ID CSCuw87174.
Affected Software
28 affected components
cisco 300 Series Managed Switch Firmware=1.4.1
cisco Sf300-08
cisco Sf300-24
cisco Sf300-24mp
cisco Sf300-24p
cisco Sf300-24pp
cisco Sf300-48
cisco Sf300-48p
cisco Sf300-48pp
cisco Sf302-08
cisco Sf302-08mp
cisco Sf302-08mpp
cisco Sf302-08p
cisco Sf302-08pp
cisco Sg300-10
cisco Sg300-10mp
cisco Sg300-10mpp
cisco Sg300-10p
cisco Sg300-10pp
cisco Sg300-10sfp
cisco Sg300-20
cisco Sg300-28
cisco Sg300-28mp
cisco Sg300-28p
cisco Sg300-28pp
cisco Sg300-52
cisco Sg300-52mp
cisco Sg300-52p
Event History
Jan 27, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1299?
CVE-2016-1299 has been rated as a high-severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2016-1299?
To fix CVE-2016-1299, upgrade the firmware of affected Cisco Small Business SG300 devices to the latest version.
3
Can CVE-2016-1299 be exploited remotely?
Yes, CVE-2016-1299 can be exploited remotely through crafted HTTPS requests.
4
Which devices are affected by CVE-2016-1299?
CVE-2016-1299 specifically affects Cisco Small Business SG300 devices running firmware version 1.4.1.x.
5
What is the impact of CVE-2016-1299?
The main impact of CVE-2016-1299 is a denial of service, resulting in an outage of HTTPS services.