CVE-2016-1303: Input Validation
Published Jan 30, 2016
·Updated
The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a crafted HTTP request, aka Bug ID CSCul65330.
Affected Software
16 affected components
Cisco 500 Series Switch Firmware=1.2.0.92
cisco Sf500-24
cisco Sf500-24p
cisco Sf500-48
cisco Sf500-48p
cisco Sg500-28
cisco Sg500-28mpp
cisco Sg500-28p
cisco Sg500-52
cisco Sg500-52mp
cisco Sg500-52p
cisco Sg500x-24
cisco Sg500x-24p
cisco Sg500x-48
cisco Sg500x-48p
cisco Sg500xg-8f8t
Event History
Jan 30, 2016
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1303?
CVE-2016-1303 has a severity rating of Medium due to its denial of service impact on affected devices.
2
How do I fix CVE-2016-1303?
To fix CVE-2016-1303, upgrade the Cisco Small Business 500 devices firmware to a version higher than 1.2.0.92.
3
What type of attack does CVE-2016-1303 allow?
CVE-2016-1303 allows remote attackers to perform a denial of service attack via crafted HTTP requests.
4
Which devices are affected by CVE-2016-1303?
CVE-2016-1303 affects Cisco Small Business 500 series devices running firmware version 1.2.0.92.
5
Is there a workaround for CVE-2016-1303 until it is patched?
There are no documented workarounds for CVE-2016-1303; upgrading the firmware is the recommended action.